7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22899
Software Genérico Networking
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Core FTP / SFTP Server v2 Build 725 was discovered to allow unauthenticated attackers to cause a Denial of Service (DoS) via a crafted packet through the SSH service.

CVE-2022-43702
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
N/A
UNKNOWN
EPSS
0.0%
2022 CWE-284 1 PoC

When the directory containing the installer does not have sufficiently restrictive file permissions, an attacker can modify (or replace) the installer to execute malicious code.

CVE-2022-39983
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2022 2 PoCs

File upload vulnerability in Pro Gamma Instant Developer RD3 22.5 r23, r30, and possibly earlier versions, allows attackers to execute arbitrary code.

CVE-2022-26305
LibreOffice General
N/A
UNKNOWN
EPSS
0.7%
2022 CWE-295 1 PoC

An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could therefore create an arbitrary certificate with a serial number and an issuer string identical to a trusted certificate which LibreOffice would present as belonging to the trusted author, potentially leading to the user to execute arbitra

CVE-2022-45063
Software Genérico General
N/A
UNKNOWN
EPSS
17.9%
2022 4 PoCs

xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.

CVE-2022-1614
WP-EMail Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 CWE-639 1 PoC

The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based anti-spamming restrictions.

CVE-2022-27287
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2022 1 PoC

D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.

CVE-2022-24958
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2022 1 PoC

drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

CVE-2022-0450
Menu Image, Icons made easy Web Windows
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

The Menu Image, Icons made easy WordPress plugin before 3.0.6 does not have authorisation and CSRF checks when saving menu settings, and does not validate, sanitise and escape them. As a result, any authenticate users, such as subscriber can update the settings or arbitrary menu and put Cross-Site Scripting payloads in them which will be triggered in the related menu in the frontend

CVE-2022-27359
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2022 1 PoC

Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a this.maildoc NULL pointer dereference.

CVE-2022-41198
SAP 3D Visual Enterprise Viewer General
N/A
UNKNOWN
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated SketchUp (.skp, SketchUp.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-36271
Software Genérico General
N/A
UNKNOWN
EPSS
1.6%
2022 1 PoC

Outbyte PC Repair Installation File 1.7.112.7856 is vulnerable to Dll Hijacking. iertutil.dll is missing so an attacker can use a malicious dll with same name and can get admin privileges.

CVE-2022-25075
Software Genérico General
N/A
UNKNOWN
EPSS
42.1%
2022 2 PoCs

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVE-2022-32024
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
11.8%
2022 0 PoCs

Car Rental Management System v1.0 is vulnerable to SQL Injection via car-rental-management-system/booking.php?car_id=.

CVE-2022-2008
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2022 1 PoC

Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-29613
SAP Employee Self Service (Fiori My Leave Request) General
N/A
UNKNOWN
EPSS
0.4%
2022 CWE-20 1 PoC

Due to insufficient input validation, SAP Employee Self Service allows an authenticated attacker with user privileges to alter employee number. On successful exploitation, the attacker can view personal details of other users causing a limited impact on confidentiality of the application.

CVE-2022-1112
Autolinks Web Windows
N/A
UNKNOWN
EPSS
0.1%
2022 CWE-79 1 PoC

The Autolinks WordPress plugin through 1.0.1 does not have CSRF check in place when updating its settings, and does not sanitise as well as escape them, which could allow attackers to perform Stored Cross-Site scripting against a logged in admin via a CSRF attack

CVE-2022-30243
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2022 1 PoC

Honeywell Alerton Visual Logic through 2022-05-04 allows unauthenticated programming writes from remote users. This enables code to be stored on the controller and then run without verification. A user with malicious intent can send a crafted packet to change and/or stop the program without the knowledge of other users, altering the controller's function. After the programming change, the program needs to be overwritten in order for the controller to restore its original operational function.

CVE-2022-1227
psgo General
N/A
UNKNOWN
EPSS
33.7%
2022 CWE-281 2 PoCs

A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.

CVE-2022-37393
Zimbra Server General
N/A
UNKNOWN
EPSS
5.1%
2022 CWE-284 1 PoC

Zimbra's sudo configuration permits the zimbra user to execute the zmslapd binary as root with arbitrary parameters. As part of its intended functionality, zmslapd can load a user-defined configuration file, which includes plugins in the form of .so files, which also execute as root.