7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3691
DeepL Pro API translation plugin Web Windows
7.5
HIGH
EPSS
1.1%
2022 1 PoC

The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.

CVE-2022-47925
csaf-validator-service General
7.5
HIGH
EPSS
1.3%
2022 CWE-20 1 PoC

The validate JSON endpoint of the Secvisogram csaf-validator-service in versions < 0.1.0 processes tests with unexpected names. This insufficient input validation of requests by an unauthenticated remote user might lead to a partial DoS of the service. Only the request of the attacker is affected by this vulnerability.

CVE-2022-24381
ASNeG/OpcUaStack General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package asneg/opcuastack are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without sending the Final closing chunk.

CVE-2022-48482
Software Genérico Windows
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

CVE-2022-23854
InTouch Access Anywhere General ⚡ nuclei
7.5
HIGH
EPSS
92.2%
2022 CWE-23 2 PoCs

AVEVA InTouch Access Anywhere versions 2020 R2 and older are vulnerable to a path traversal exploit that could allow an unauthenticated user with network access to read files on the system outside of the secure gateway web server.

CVE-2022-38870
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
52.4%
2022 0 PoCs

Free5gc v3.2.1 is vulnerable to Information disclosure.

CVE-2022-50977
VibroLine VLX1 HD 5.0 Web
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via HTTP.

CVE-2022-30746
Smart Things Web
7.5
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

CVE-2022-25867
io.socket:socket.io-client General
7.5
HIGH
EPSS
0.9%
2022 1 PoC

The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.

CVE-2022-37301
Modicon M340 CPU (part numbers BMXP34*) General
7.5
HIGH
EPSS
0.5%
2022 CWE-191 1 PoC

A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)

CVE-2022-45269
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
27.4%
2022 0 PoCs

A directory traversal vulnerability in the component SCS.Web.Server.SPI/1.0 of Linx Sphere LINX 7.35.ST15 allows attackers to read arbitrary files.

CVE-2022-1579
Login Block IPs General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.

CVE-2022-1444
radareorg/radare2 General
7.5
HIGH
EPSS
0.3%
2022 CWE-416 2 PoCs

heap-use-after-free in GitHub repository radareorg/radare2 prior to 5.7.0. This vulnerability is capable of inducing denial of service.

CVE-2022-4636
KVM ACR1020A-T General
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.

CVE-2022-35290
SAP Authenticator for Android General
7.5
HIGH
EPSS
0.3%
2022 CWE-200 2 PoCs

Under certain conditions SAP Authenticator for Android allows an attacker to access information which would otherwise be restricted.

CVE-2022-24190
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The /device/acceptBind end-point for Ourphoto App version 1.4.1 does not require authentication or authorization. The user_token header is not implemented or present on this end-point. An attacker can send a request to bind their account to any users picture frame, then send a POST request to accept their own bind request, without the end-users approval or interaction.

CVE-2022-34126
Software Genérico Web
7.5
HIGH
EPSS
1.6%
2022 1 PoC

The Activity plugin before 3.1.1 for GLPI allows reading local files via directory traversal in the front/cra.send.php file parameter.

CVE-2022-21566
Applications Framework Web Database
7.5
HIGH
EPSS
3.2%
2022 1 PoC

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.9-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

CVE-2022-40874
Software Genérico Web
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request.

CVE-2022-23648
containerd DevOps Windows
7.5
HIGH
EPSS
5.8%
2022 CWE-200 2 PoCs

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation.