2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-43939
🔥 KEV Pentaho Business Analytics Server General ⚡ nuclei
8.6
HIGH
EPSS
93.3%
2022 CWE-647 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CVE-2022-4800
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-940 1 PoC

Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-50806
4images Web
8.6
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbitrary commands by accessing a specific categories.php endpoint with a crafted cat_id parameter.

CVE-2022-29477
iota All-In-One Security Kit Web
8.6
HIGH
EPSS
0.3%
2022 CWE-798 1 PoC

An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP header can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-50898
NanoCMS Web
8.6
HIGH
EPSS
0.4%
2022 CWE-434 1 PoC

NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory by exploiting the page creation mechanism without proper input sanitization.

CVE-2022-27830
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-30756
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.

CVE-2022-33703
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in CACertificateInfo prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-50921
WOW21 General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions during service startup.

CVE-2022-50938
CONTPAQ AdminPAQ General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.

CVE-2022-50913
TCQ General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code with elevated system privileges. Attackers can insert a malicious executable in the service path to gain elevated access during service restart or system reboot.

CVE-2022-50920
Sandboxie Plus Windows
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2022-21430
Communications Billing and Revenue Management Database
8.5
HIGH
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of O

CVE-2022-50915
PTPublisher General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

PTPublisher 2.3.4 contains an unquoted service path vulnerability in the PTProtect service that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Primera Technology\PTPublisher\UsbFlashDongleService.exe' to inject malicious executables and gain system-level access.

CVE-2022-30713
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-30710
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-50935
FLAME II MODEM USB Windows
8.5
HIGH
EPSS
0.1%
2022 CWE-428 1 PoC

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

CVE-2022-50693
Splashtop General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and escalate privileges.

CVE-2022-27829
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-33704
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.