7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3382
HIWIN Robot System Software General
7.5
HIGH
EPSS
0.2%
2022 CWE-284 1 PoC

HIWIN Robot System Software version 3.3.21.9869 does not properly address the terminated command source. As a result, an attacker could craft code to disconnect HRSS and the controller and cause a denial-of-service condition.

CVE-2022-24381
ASNeG/OpcUaStack General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-21213
mout Web
7.5
HIGH
EPSS
1.5%
2022 4 PoCs

This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn mixes objects into the target object, recursively mixing existing child objects as well. In both cases, the key used to access the target object recursively is not checked, leading to exploiting this vulnerability. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7792](https://security.snyk.io/vuln/SNYK-JS-MOUT-1014544).

CVE-2022-41649
OpenImageIO General
7.5
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted TIFF file can cause a read of adjacent heap memory, which can leak sensitive process information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-21940
System Configuration Tool (SCT) Web
7.5
HIGH
EPSS
0.1%
2022 CWE-614 1 PoC

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

CVE-2022-24375
node-opcua General
7.5
HIGH
EPSS
0.6%
2022 1 PoC

The package node-opcua before 2.74.0 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.

CVE-2022-3780
Remote Desktop Manager Database
7.5
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Database connections on deleted users could stay active on MySQL data sources in Remote Desktop Manager 2022.3.7 and below which allow deleted users to access unauthorized data. This issue affects : Remote Desktop Manager 2022.3.7 and prior versions.

CVE-2022-37255
Software Genérico General
7.5
HIGH
EPSS
9.3%
2022 1 PoC

TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL075526460603.

CVE-2022-1723
jgraph/drawio General
7.5
HIGH
EPSS
0.9%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.6.

CVE-2022-34460
BIOS General
7.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-21422
Communications Billing and Revenue Management Database
7.5
HIGH
EPSS
0.9%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in takeover of Oracle Communications Billing and Revenue Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.

CVE-2022-47941
Software Genérico Windows
7.5
HIGH
EPSS
2.0%
2022 1 PoC

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.

CVE-2022-4244
RHINT Camel-K-1.10.1 General
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file paths, it may be possible to access arbitrary files and directories stored on the file system, including application source code, configuration, and other critical system files.

CVE-2022-50978
VibroLine VLX1 HD 5.0 General
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

CVE-2022-25027
Software Genérico General
7.5
HIGH
EPSS
1.3%
2022 1 PoC

The Forgotten Password functionality of Rocket TRUfusion Portal v7.9.2.1 allows remote attackers to bypass authentication and access restricted pages by validating the user's session token when the "Password forgotten?" button is clicked.

CVE-2022-38870
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2022 0 PoCs

Free5gc v3.2.1 is vulnerable to Information disclosure.

CVE-2022-21466
Commerce Guided Search / Oracle Commerce Experience Manager Web Database
7.5
HIGH
EPSS
1.7%
2022 1 PoC

Vulnerability in the Oracle Commerce Guided Search product of Oracle Commerce (component: Tools and Frameworks). The supported version that is affected is 11.3.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Commerce Guided Search accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-42999
Software Genérico General
7.5
HIGH
EPSS
12.0%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.

CVE-2022-0281
microweber/microweber General ⚡ nuclei
7.5
HIGH
EPSS
18.6%
2022 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-50977
VibroLine VLX1 HD 5.0 Web
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.