7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25908
create-choo-electron General
7.4
HIGH
EPSS
1.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-29217
pyjwt General
7.4
HIGH
EPSS
0.4%
2022 CWE-327 1 PoC

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get support for all algorithms, or specify a single algorithm. The issue is not that big as `algorithms=jwt.algorithms.get_default_algorithms()` has to be used. Users should upgrade to v2.4.0 to receive a patch for this issue. As a workaround, always

CVE-2022-25855
create-choo-app3 General
7.4
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.

CVE-2022-21615
Enterprise Data Quality Web Database
7.4
HIGH
EPSS
1.6%
2022 1 PoC

Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Data Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unautho

CVE-2022-25350
puppet-facter General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.

CVE-2022-21810
smartctl General
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.

CVE-2022-26964
Software Genérico General
7.4
HIGH
EPSS
0.3%
2022 1 PoC

Weak password derivation for export in Devolutions Remote Desktop Manager before 2022.1 allows information disclosure via a password brute-force attack. An error caused base64 to be decoded.

CVE-2022-25906
is-http2 Web
7.4
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other checks, and sandboxes being employed to the isH2 function.

CVE-2022-1809
radareorg/radare2 General
7.4
HIGH
EPSS
0.3%
2022 CWE-824 1 PoC

Access of Uninitialized Pointer in GitHub repository radareorg/radare2 prior to 5.7.0.

CVE-2022-25171
p4 General
7.4
HIGH
EPSS
1.9%
2022 1 PoC

The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization

CVE-2022-25890
wifey General
7.4
HIGH
EPSS
1.5%
2022 CWE-78 1 PoC

All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input sanitization.

CVE-2022-4502
openemr/openemr Web
7.3
HIGH
EPSS
4.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-21803
nconf General
7.3
HIGH
EPSS
0.9%
2022 2 PoCs

This affects the package nconf before 0.11.4. When using the memory engine, it is possible to store a nested JSON representation of the configuration. The .set() function, that is responsible for setting the configuration properties, is vulnerable to Prototype Pollution. By providing a crafted property, it is possible to modify the properties on the Object.prototype.

CVE-2022-1073
Automatic Question Paper Generator General
7.3
HIGH
EPSS
0.3%
2022 CWE-640 1 PoC

A vulnerability was found in Automatic Question Paper Generator 1.0. It has been declared as critical. An attack leads to privilege escalation. The attack can be launched remotely.

CVE-2022-37331
Open Babel General
7.3
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the Gaussian format orientation functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-3875
Passwordstate Web
7.3
HIGH
EPSS
0.1%
2022 CWE-302 2 PoCs

A vulnerability classified as critical was found in Click Studios Passwordstate and Passwordstate Browser Extension Chrome. This vulnerability affects unknown code of the component API. The manipulation leads to authentication bypass by assumed-immutable data. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216244.

CVE-2022-4737
Blood Bank Management System Web Database
7.3
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Blood Bank Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument username/password leads to sql injection. The attack may be initiated remotely. The identifier VDB-216773 was assigned to this vulnerability.

CVE-2022-22521
Benchmark Programming Tool General
7.3
HIGH
EPSS
0.1%
2022 CWE-732 2 PoCs

In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin.

CVE-2022-2766
Loan Management System Web Database
7.3
HIGH
EPSS
0.3%
2022 CWE-89 1 PoC

A vulnerability was found in SourceCodester Loan Management System. It has been rated as critical. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument password leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-206162 is the identifier assigned to this vulnerability.

CVE-2022-0272
detekt/detekt General
7.3
HIGH
EPSS
0.3%
2022 CWE-611 1 PoC

Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.