7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22138
fast-string-search General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading from non-permitted locations and cause a segmentation fault due to the violation.

CVE-2022-43343
Software Genérico General
7.5
HIGH
EPSS
4.1%
2022 1 PoC

N-Prolog v1.91 was discovered to contain a global buffer overflow vulnerability in the function gettoken() at Main.c.

CVE-2022-45957
Software Genérico Networking
7.5
HIGH
EPSS
2.0%
2022 2 PoCs

ZTE ZXHN-H108NS router with firmware version H108NSV1.0.7u_ZRD_GR2_A68 is vulnerable to remote stack buffer overflow.

CVE-2022-0391
python General
7.5
HIGH
EPSS
1.2%
2022 CWE-74 1 PoC

A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. This flaw affects Python versions prior to 3.10.0b1, 3.9.5, 3.8.11, 3.7.11 and 3.6.14.

CVE-2022-23648
containerd DevOps Windows
7.5
HIGH
EPSS
5.8%
2022 CWE-200 2 PoCs

containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation on Linux with a specially-crafted image configuration could gain access to read-only copies of arbitrary files and directories on the host. This may bypass any policy-based enforcement on container setup (including a Kubernetes Pod Security Policy) and expose potentially sensitive information. Kubernetes and crictl can both be configured to use containerd’s CRI implementation.

CVE-2022-25851
jpeg-js General
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.

CVE-2022-46770
Software Genérico Networking
7.5
HIGH
EPSS
16.9%
2022 1 PoC

qubes-mirage-firewall (aka Mirage firewall for QubesOS) 0.8.x through 0.8.3 allows guest OS users to cause a denial of service (CPU consumption and loss of forwarding) via a crafted multicast UDP packet (IP address range of 224.0.0.0 through 239.255.255.255).

CVE-2022-24897
xwiki-commons Web
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

APIs to evaluate content with Velocity is a package for APIs to evaluate content with Velocity. Starting with version 2.3 and prior to 12.6.7, 12.10.3, and 13.0, the velocity scripts are not properly sandboxed against using the Java File API to perform read or write operations on the filesystem. Writing an attacking script in Velocity requires the Script rights in XWiki so not all users can use it, and it also requires finding an XWiki API which returns a File. The problem has been patched in versions 12.6.7, 12.10.3, and 13.0. There is no easy workaround for fixing this vulnerability other th

CVE-2022-25352
libnested Web
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

The package libnested before 1.5.2 are vulnerable to Prototype Pollution via the set function in index.js. **Note:** This vulnerability derives from an incomplete fix for [CVE-2020-28283](https://security.snyk.io/vuln/SNYK-JS-LIBNESTED-1054930)

CVE-2022-36324
RUGGEDCOM RM1224 LTE(4G) EU General
7.5
HIGH
EPSS
1.5%
2022 CWE-770 1 PoC

Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.

CVE-2022-26043
OAS Platform General
7.5
HIGH
EPSS
0.3%
2022 CWE-306 1 PoC

An external config control vulnerability exists in the OAS Engine SecureAddSecurity functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to the creation of a custom Security Group. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-23820
Ryzen™ 3000 series Desktop Processors “Matisse" General
7.5
HIGH
EPSS
0.2%
2022 3 PoCs

Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

CVE-2022-45546
Software Genérico General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

Information Disclosure in Authentication Component of ScreenCheck BadgeMaker 2.6.2.0 application allows internal attacker to obtain credentials for authentication via network sniffing.

CVE-2022-23308
Software Genérico General
7.5
HIGH
EPSS
0.1%
2022 1 PoC

valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

CVE-2022-27673
AMD Link Android General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Insufficient access controls in the AMD Link Android app may potentially result in information disclosure.

CVE-2022-3119
OAuth client Single Sign On for WordPress ( OAuth 2.0 SSO ) Web Windows
7.5
HIGH
EPSS
0.2%
2022 CWE-287 1 PoC

The OAuth client Single Sign On WordPress plugin before 3.0.4 does not have authorisation and CSRF when updating its settings, which could allow unauthenticated attackers to update them and change the OAuth endpoints to ones they controls, allowing them to then be authenticated as admin if they know the correct email address

CVE-2022-21231
deep-get-set Web
7.5
HIGH
EPSS
0.2%
2022 2 PoCs

All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-7715](https://security.snyk.io/vuln/SNYK-JS-DEEPGETSET-598666)

CVE-2022-25907
ts-deepmerge General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.

CVE-2022-48482
Software Genérico Windows
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

CVE-2022-21167
Masuit.Tools.Core General
7.5
HIGH
EPSS
0.9%
2022 1 PoC

All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established, because this socket client transmission does not have the appropriate restrictions or type bindings for the BinaryFormatter.