7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25377
Software Genérico General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to be vulnerable, APP_STORAGE_CERTIFICATES/.well-known/acme-challenge must exist on disk. (This pathname is automatically created if the user chooses to install Let's Encrypt certificates via Appwrite.)

CVE-2022-0203
crater-invoice/crater General
7.5
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository crater-invoice/crater prior to 6.0.2.

CVE-2022-28750
Zoom On-Premise Meeting Connector Zone Controller (ZC) General
7.5
HIGH
EPSS
0.6%
2022 CWE-121 1 PoC

Zoom On-Premise Meeting Connector Zone Controller (ZC) before version 4.8.20220419.112 fails to properly parse STUN error codes, which can result in memory corruption and could allow a malicious actor to crash the application. In versions older than 4.8.12.20211115, this vulnerability could also be leveraged to execute arbitrary code.

CVE-2022-40898
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An issue discovered in Python Packaging Authority (PyPA) Wheel 0.37.1 and earlier allows remote attackers to cause a denial of service via attacker controlled input to wheel cli.

CVE-2022-22781
Zoom Client for Meetings for MacOS (Standard and for IT Admin) General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) prior to version 5.9.6 failed to properly check the package version during the update process. This could lead to a malicious actor updating an unsuspecting user’s currently installed version to a less secure version.

CVE-2022-43326
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos Alliance Omnia MPX Node 1.0.0-1.4.[*] allows attackers to arbitrarily change user and Administrator account passwords.

CVE-2022-50978
VibroLine VLX1 HD 5.0 General
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

CVE-2022-1430
octoprint/octoprint Web
7.5
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.

CVE-2022-23831
AMD μProf Windows
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service.

CVE-2022-2633
All-in-One Video Gallery Web Windows ⚡ nuclei
7.5
HIGH
EPSS
88.4%
2022 0 PoCs

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

CVE-2022-25304
opcua General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

All versions of package opcua; all versions of package asyncua are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-23082
CureKit General
7.5
HIGH
EPSS
0.6%
2022 CWE-22 2 PoCs

In CureKit versions v1.0.1 through v1.1.3 are vulnerable to path traversal as the function isFileOutsideDir fails to sanitize the user input which may lead to path traversal.

CVE-2022-37620
Software Genérico General
7.5
HIGH
EPSS
0.5%
2022 1 PoC

A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.

CVE-2022-31474
BackupBuddy General ⚡ nuclei
7.5
HIGH
EPSS
92.3%
2022 CWE-22 0 PoCs

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in iThemes BackupBuddy allows Path Traversal.This issue affects BackupBuddy: from 8.5.8.0 through 8.7.4.1.

CVE-2022-4140
Welcart e-Commerce Web Windows ⚡ nuclei
7.5
HIGH
EPSS
54.3%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server

CVE-2022-47925
csaf-validator-service General
7.5
HIGH
EPSS
1.3%
2022 CWE-20 1 PoC

The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a partial DoS of the service. Only the request of the attacker is affected by this vulnerability.

CVE-2022-35290
SAP Authenticator for Android General
7.5
HIGH
EPSS
0.3%
2022 CWE-200 2 PoCs

Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

CVE-2022-25867
io.socket:socket.io-client General
7.5
HIGH
EPSS
0.9%
2022 1 PoC

The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.

CVE-2022-25882
onnx General
7.5
HIGH
EPSS
5.8%
2022 CWE-22 1 PoC

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

CVE-2022-4450
OpenSSL General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is responsible for freeing those buffers. It is possible to construct a PEM file that results in 0 bytes of payload data. In this case PEM_read_bio_ex() will return a failure code but will populate the header argument with a pointer to a buffer that has already been freed. If the ca