7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2321
heroiclabs/nakama General
7.5
HIGH
EPSS
0.3%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository heroiclabs/nakama prior to 3.13.0. This results in login brute-force attacks.

CVE-2022-21598
Siebel Core - DB Deployment and Configuration Web Database
7.5
HIGH
EPSS
1.2%
2022 1 PoC

Vulnerability in the Siebel Core - DB Deployment and Configuration product of Oracle Siebel CRM (component: Repository Utilities). Supported versions that are affected are 22.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Core - DB Deployment and Configuration. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Siebel Core - DB Deployment and Configuration accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (C

CVE-2022-32777
AVideo Web
7.5
HIGH
EPSS
1.1%
2022 CWE-732 1 PoC

An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and the pass cookie miss the HttpOnly flag, making them accessible via JavaScript. The session cookie also misses the secure flag, which allows the session cookie to be leaked over non-HTTPS connections. This could allow an attacker to steal the session cookie via crafted HTTP requests.This vulnerabilty is for the session cookie which can be leaked via JavaScript.

CVE-2022-42732
syngo Dynamics General
7.5
HIGH
EPSS
0.3%
2022 CWE-73 1 PoC

A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.

CVE-2022-3786
OpenSSL General
7.5
HIGH
EPSS
27.3%
2022 3 PoCs

A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure to construct a path to a trusted issuer. An attacker can craft a malicious email address in a certificate to overflow an arbitrary number of bytes containing the `.' character (decimal 46) on the stack. This buffer overflow could result in a crash (causing a denial of service). In

CVE-2022-21144
libxmljs General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.

CVE-2022-42276
NVIDIA DGX servers General
7.5
HIGH
EPSS
0.0%
2022 CWE-288 1 PoC

NVIDIA DGX A100 contains a vulnerability in SBIOS in the SmiFlash, where a local user with elevated privileges can read, write and erase flash, which may lead to code execution, escalation of privileges, denial of service, and information disclosure. The scope of impact can extend to other components.

CVE-2022-2633
All-in-One Video Gallery Web Windows ⚡ nuclei
7.5
HIGH
EPSS
88.4%
2022 0 PoCs

The All-in-One Video Gallery plugin for WordPress is vulnerable to arbitrary file downloads and blind server-side request forgery via the 'dl' parameter found in the ~/public/video.php file in versions up to, and including 2.6.0. This makes it possible for unauthenticated users to download sensitive files hosted on the affected server and forge requests to the server.

CVE-2022-42124
Software Genérico General
7.5
HIGH
EPSS
1.2%
2022 2 PoCs

ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted payload injected into the 'name' field of a layout prototype.

CVE-2022-4794
AAWP Web Networking Windows
7.5
HIGH
EPSS
0.5%
2022 1 PoC

The AAWP WordPress plugin before 3.12.3 can be used to abuse trusted domains to load malware or other files through it (Reflected File Download) to bypass firewall rules in companies.

CVE-2022-25850
github.com/hoppscotch/proxyscotch Web
7.5
HIGH
EPSS
0.3%
2022 1 PoC

The package github.com/hoppscotch/proxyscotch before 1.0.0 are vulnerable to Server-side Request Forgery (SSRF) when interceptor mode is set to proxy. It occurs when an HTTP request is made by a backend server to an untrusted URL submitted by a user. It leads to a leakage of sensitive information from the server.

CVE-2022-1711
jgraph/drawio General ⚡ nuclei
7.5
HIGH
EPSS
35.4%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository jgraph/drawio prior to 18.0.5.

CVE-2022-21562
SOA Suite Web Database
7.5
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Fabric Layer). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2022-45640
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).

CVE-2022-21622
SOA Suite Web Database
7.5
HIGH
EPSS
1.3%
2022 1 PoC

Vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware (component: Adapters). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle SOA Suite. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle SOA Suite accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).

CVE-2022-48482
Software Genérico Windows
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/download directory traversal. Files may have credentials, full backups, call recordings, and chat logs.

CVE-2022-4621
Sanyo CCTV Network Camera Web
7.5
HIGH
EPSS
0.1%
2022 CWE-352 1 PoC

Panasonic Sanyo CCTV Network Cameras versions 1.02-05 and 2.03-0x are vulnerable to CSRFs that can be exploited to allow an attacker to perform changes with administrator level privileges.

CVE-2022-21192
serve-lite General
7.5
HIGH
EPSS
1.4%
2022 CWE-22 1 PoC

All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().

CVE-2022-25867
io.socket:socket.io-client General
7.5
HIGH
EPSS
0.9%
2022 1 PoC

The package io.socket:socket.io-client before 2.0.1 are vulnerable to NULL Pointer Dereference when parsing a packet with with invalid payload format.

CVE-2022-32485
CPG BIOS General
7.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.