2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25866
czproject/git-php Web
8.1
HIGH
EPSS
2.0%
2022 1 PoC

The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that additional flags can be set. The additional flags can be used to perform a command injection.

CVE-2022-41674
Software Genérico General
8.1
HIGH
EPSS
0.5%
2022 2 PoCs

An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.

CVE-2022-39882
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2022 CWE-787 1 PoC

Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.

CVE-2022-4815
Pentaho Business Analytics Server General
8.0
HIGH
EPSS
0.5%
2022 CWE-502 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 

CVE-2022-0930
microweber/microweber Web
8.0
HIGH
EPSS
0.5%
2022 CWE-434 1 PoC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-21934
Metasys ADS/ADX/OAS server General
8.0
HIGH
EPSS
0.3%
2022 CWE-620 1 PoC

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.

CVE-2022-22769
TIBCO EBX Web
8.0
HIGH
EPSS
0.4%
2022 1 PoC

The Web server component of TIBCO Software Inc.'s TIBCO EBX, TIBCO EBX, TIBCO EBX, TIBCO EBX Add-ons, TIBCO EBX Add-ons, TIBCO EBX Add-ons, and TIBCO Product and Service Catalog powered by TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 5.8.124 and below, TIBCO EBX: versions 5.9.3, 5.9.4, 5

CVE-2022-22776
TIBCO BusinessConnect Trading Community Management Web
8.0
HIGH
EPSS
0.6%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

CVE-2022-2027
kromitgmbh/titra General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVE-2022-22765
BD Viper LT System Windows
8.0
HIGH
EPSS
0.1%
2022 CWE-798 1 PoC

BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). BD Viper LT system versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this vulnerability.

CVE-2022-30577
TIBCO EBX Web
8.0
HIGH
EPSS
0.9%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8.

CVE-2022-2287
vim/vim General
8.0
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVE-2022-21668
pipenv General
8.0
HIGH
EPSS
1.5%
2022 CWE-20 1 PoC

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which will cause victims who use pipenv to install the requirements file to download dependencies from a package index server controlled by the attacker. By embedding malicious code in packages served from their malicious index server, the attacker can trigger arbitrary remote code execution (RCE) on the victims' systems. If a

CVE-2022-40472
Software Genérico Cloud
8.0
HIGH
EPSS
0.7%
2022 1 PoC

ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.

CVE-2022-39950
Fortinet FortiAnalyzer, FortiManager Web Networking
8.0
HIGH
EPSS
0.7%
2022 1 PoC

An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.

CVE-2022-41853
hsqldb Database
8.0
HIGH
EPSS
70.1%
2022 CWE-470 1 PoC

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classe

CVE-2022-2420
Web Manager Web
8.0
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.

CVE-2022-1544
luyadev/yii-helpers General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

CVE-2022-0964
star7th/showdoc Web
8.0
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Stored XSS viva .webmv file upload in GitHub repository star7th/showdoc prior to 2.10.4.