7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0572
vim/vim General
8.4
HIGH
EPSS
1.8%
2022 CWE-122 2 PoCs

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-2054
nuitka/nuitka General
8.4
HIGH
EPSS
0.1%
2022 CWE-94 1 PoC

Code Injection in GitHub repository nuitka/nuitka prior to 0.9.

CVE-2022-37397
Yugabyte DB Windows
8.3
HIGH
EPSS
0.5%
2022 CWE-287 1 PoC

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

CVE-2022-4691
usememos/memos Web
8.3
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-0258
pimcore/pimcore Database
8.3
HIGH
EPSS
0.0%
2022 CWE-89 1 PoC

pimcore is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CVE-2022-4811
usememos/memos General
8.3
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

CVE-2022-1727
jgraph/drawio General
8.3
HIGH
EPSS
1.1%
2022 CWE-20 1 PoC

Improper Input Validation in GitHub repository jgraph/drawio prior to 18.0.6.

CVE-2022-21134
Software Genérico Web
8.3
HIGH
EPSS
0.4%
2022 CWE-347 1 PoC

A firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-33148
AVideo Web Database
8.3
HIGH
EPSS
2.5%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the title parameter.

CVE-2022-4689
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-2732
openemr/openemr General
8.3
HIGH
EPSS
0.3%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-33149
AVideo Web Database
8.3
HIGH
EPSS
3.2%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the CloneSite plugin, allowing an attacker to inject SQL by manipulating the url parameter.

CVE-2022-4809
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1285
gogs/gogs General
8.3
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

CVE-2022-4615
openemr/openemr Web
8.3
HIGH
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-21424
Communications Billing and Revenue Management Database
8.3
HIGH
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). The supported version that is affected is 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Communications Billing and Revenue Management accessible data as well as unauthorized access t

CVE-2022-0224
dolibarr/dolibarr Database
8.3
HIGH
EPSS
0.5%
2022 CWE-89 1 PoC

dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CVE-2022-4847
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-941 1 PoC

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-34652
AVideo Web Database
8.3
HIGH
EPSS
2.5%
2022 CWE-89 1 PoC

A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to a SQL injection. An attacker can send an HTTP request to trigger this vulnerability.This vulnerability exists in the Live Schedules plugin, allowing an attacker to inject SQL by manipulating the description parameter.