2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-31705
VMware ESXi, VMware Workstation Pro / Player, VMware Fusion Pro / Fusion (Fusion), VMware Cloud Foundation Cloud
8.2
HIGH
EPSS
2.5%
2022 1 PoC

VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

CVE-2022-21571
VM VirtualBox Database
8.2
HIGH
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.36. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availabilit

CVE-2022-28759
Zoom On-Premise Meeting Connector MMR General
8.2
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-0086
transloadit/uppy General
8.2
HIGH
EPSS
0.3%
2022 CWE-918 1 PoC

uppy is vulnerable to Server-Side Request Forgery (SSRF)

CVE-2022-28758
Zoom On-Premise Meeting Connector MMR General
8.2
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.

CVE-2022-24818
geotools Web
8.2
HIGH
EPSS
8.2%
2022 CWE-20 1 PoC

GeoTools is an open source Java library that provides tools for geospatial data. The GeoTools library has a number of data sources that can perform unchecked JNDI lookups, which in turn can be used to perform class deserialization and result in arbitrary code execution. Similar to the Log4J case, the vulnerability can be triggered if the JNDI names are user-provided, but requires admin-level login to be triggered. The lookups are now restricted in GeoTools 26.4, GeoTools 25.6, and GeoTools 24.6. Users unable to upgrade should ensure that any downstream application should not allow usage of rem

CVE-2022-48474
Control de Ciber General
8.2
HIGH
EPSS
1.7%
2022 CWE-400 1 PoC

Control de Ciber, in its 1.650 version, is affected by a Denial of Service condition through the version function. Sending a malicious request could cause the server to check if an unrecognized component is up to date, causing a memory failure error that shuts down the process.

CVE-2022-35874
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `ssid` and `ssid_hex` configuration parameters, as used within the `testWifiAP` XCMD handler

CVE-2022-48475
Control de Ciber General
8.2
HIGH
EPSS
0.7%
2022 CWE-400 1 PoC

Buffer Overflow vulnerability in Control de Ciber version 1.650, in the printing function. Sending a modified request by the attacker could cause a Buffer Overflow when the adminitrator tries to accept or delete the print query created by the request.

CVE-2022-38491
Software Genérico General
8.2
HIGH
EPSS
0.3%
2022 1 PoC

An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.

CVE-2022-1173
getgrav/grav Web
8.2
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

stored xss in GitHub repository getgrav/grav prior to 1.7.33.

CVE-2022-0894
pimcore/pimcore Web
8.2
HIGH
EPSS
0.0%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 10.4.0.

CVE-2022-22999
My Cloud Web Cloud
8.2
HIGH
EPSS
0.6%
2022 CWE-79 1 PoC

Western Digital My Cloud devices are vulnerable to a cross side scripting vulnerability that can allow a malicious user with elevated privileges access to drives being backed up to construct and inject JavaScript payloads into an authenticated user's browser. As a result, it may be possible to gain control over the authenticated session, steal data, modify settings, or redirect the user to malicious websites. The scope of impact can extend to other components.

CVE-2022-0871
gogs/gogs General
8.2
HIGH
EPSS
1.0%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.

CVE-2022-35877
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` configuration parameter, as used within the `testWifiAP` XCMD handler

CVE-2022-31194
DSpace Web
8.2
HIGH
EPSS
0.8%
2022 CWE-22 1 PoC

DSpace open source software is a repository application which provides durable access to digital resources. dspace-jspui is a UI component for DSpace. The JSPUI resumable upload implementations in SubmissionController and FileUploadRequest are vulnerable to multiple path traversal attacks, allowing an attacker to create files/directories anywhere on the server writable by the Tomcat/DSpace user, by modifying some request parameters during submission. This path traversal can only be executed by a user with special privileges (submitter rights). This vulnerability only impacts the JSPUI. Users a

CVE-2022-31363
Software Genérico Web
8.2
HIGH
EPSS
0.1%
2022 1 PoC

Cypress : https://www.infineon.com/ Cypress Bluetooth Mesh SDK BSA0107_05.01.00-BX8-AMESH-08 is affected by: Buffer Overflow. The impact is: execute arbitrary code (remote). The component is: affected function is pb_transport_handle_frag_. ¶¶ In Cypress Bluetooth Mesh SDK, there is an out-of-bound write vulnerability that can be triggered during mesh provisioning. Because there is no check for mismatched SegN and TotalLength in Transaction Start PDU.

CVE-2022-33938
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.2%
2022 CWE-134 1 PoC

A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-41966
xstream General
8.2
HIGH
EPSS
2.5%
2022 CWE-120 1 PoC

XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only

CVE-2022-0860
cobbler/cobbler General
8.2
HIGH
EPSS
0.7%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.