2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0565
pimcore/pimcore Web
7.6
HIGH
EPSS
0.1%
2022 CWE-79 1 PoC

Cross-site Scripting in Packagist pimcore/pimcore prior to 10.3.1.

CVE-2022-1291
hhurz/tableexport.jquery.plugin Web
7.6
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

XSS vulnerability with default `onCellHtmlData` function in GitHub repository hhurz/tableexport.jquery.plugin prior to 1.25.0. Transmitting cookies to third-party servers. Sending data from secure sessions to third-party servers

CVE-2022-1238
radareorg/radare2 Web
7.6
HIGH
EPSS
0.3%
2022 CWE-787 2 PoCs

Out-of-bounds Write in libr/bin/format/ne/ne.c in GitHub repository radareorg/radare2 prior to 5.6.8. This vulnerability is heap overflow and may be exploitable. For more general description of heap buffer overflow, see [CWE](https://cwe.mitre.org/data/definitions/122.html).

CVE-2022-27835
Samsung Mobile Devices General
7.6
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper boundary check in UWB firmware prior to SMR Apr-2022 Release 1 allows arbitrary memory write.

CVE-2022-4746
FluentAuth Web Windows
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass the IP-based blocks set by the plugin.

CVE-2022-28750
Zoom On-Premise Meeting Connector Zone Controller (ZC) General
7.5
HIGH
EPSS
0.6%
2022 CWE-121 1 PoC

Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this vulnerability could also be leveraged to execute arbitrary code.

CVE-2022-45177
Software Genérico Web
7.5
HIGH
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

CVE-2022-32287
Apache UIMA Web
7.5
HIGH
EPSS
0.8%
2022 CWE-22 1 PoC

A relative path traversal vulnerability in a FileUtil class used by the PEAR management component of Apache UIMA allows an attacker to create files outside the designated target directory using carefully crafted ZIP entry names. This issue affects Apache UIMA Apache UIMA version 3.3.0 and prior versions. Note that PEAR files should never be installed into an UIMA installation from untrusted sources because PEAR archives are executable plugins that will be able to perform any actions with the same privileges as the host Java Virtual Machine.

CVE-2022-4550
User Activity Web Windows
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to retrieve the IP address of the request, which could lead to IP spoofing

CVE-2022-46352
SCALANCE X204RNA (HSR) General
7.5
HIGH
EPSS
0.5%
2022 CWE-400 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). Specially crafted PROFINET DCP packets could cause a denial of service condition of affected products.

CVE-2022-21634
GraalVM Enterprise Edition Database
7.5
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: LLVM Interpreter). Supported versions that are affected are Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GraalVM Enterprise Edition. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS

CVE-2022-21935
Metasys ADS/ADX/OAS server General
7.5
HIGH
EPSS
0.2%
2022 CWE-620 1 PoC

A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.

CVE-2022-42999
Software Genérico General
7.5
HIGH
EPSS
12.0%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.

CVE-2022-0281
microweber/microweber General ⚡ nuclei
7.5
HIGH
EPSS
18.6%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-24716
icingaweb2 General ⚡ nuclei
7.5
HIGH
EPSS
93.1%
2022 CWE-22 7 PoCs

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

CVE-2022-42125
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Zip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows attackers to create or overwrite existing files on the filesystem via the deployment of a malicious plugin/module.

CVE-2022-45957
Software Genérico Networking
7.5
HIGH
EPSS
2.0%
2022 2 PoCs

ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

CVE-2022-25345
@discordjs/opus General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package @discordjs/opus are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.

CVE-2022-24756
bareos General
7.5
HIGH
EPSS
0.8%
2022 CWE-401 1 PoC

Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, a failed PAM authentication will leak a small amount of memory. An attacker that is able to use the PAM Console (i.e. by knowing the shared secret or via the WebUI) can flood the Director with failing login attempts which will eventually lead to an out-of-memory condition in which the Director will not work anymore. Bareos Director versions 21.1.0, 20.0.6 and 19.2.12 contain a Bugf

CVE-2022-21500
User Management Web Database ⚡ nuclei
7.5
HIGH
EPSS
94.0%
2022 2 PoCs

Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle E-Business Suite accessible data. Note: Authentication is required for successful attack, however the user may be self-registered. <br> <br>Oracle E-Business Suite 12.1 is not impacted by this vulnerability. Customers should