7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-31176
grafana-image-renderer DevOps Web
8.3
HIGH
EPSS
0.6%
2022 CWE-200 1 PoC

Grafana Image Renderer is a Grafana backend plugin that handles rendering of panels & dashboards to PNGs using a headless browser (Chromium/Chrome). An internal security review identified an unauthorized file disclosure vulnerability. It is possible for a malicious user to retrieve unauthorized files under some network conditions or via a fake datasource (if user has admin permissions in Grafana). All Grafana installations should be upgraded to version 3.6.1 as soon as possible. As a workaround it is possible to [disable HTTP remote rendering](https://grafana.com/docs/grafana/latest/setup-graf

CVE-2022-4809
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1285
gogs/gogs General
8.3
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.

CVE-2022-4689
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-4847
usememos/memos General
8.3
HIGH
EPSS
0.3%
2022 CWE-941 1 PoC

Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4811
usememos/memos General
8.3
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key vulnerability in usememos usememos/memos.This issue affects usememos/memos before 0.9.1.

CVE-2022-45805
Paytm Payment Gateway Database ⚡ nuclei
8.2
HIGH
EPSS
2.8%
2022 CWE-89 0 PoCs

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.

CVE-2022-32488
CPG BIOS General
8.2
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.

CVE-2022-21571
VM VirtualBox Database
8.2
HIGH
EPSS
0.2%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.36. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availabilit

CVE-2022-0080
mruby/mruby General
8.2
HIGH
EPSS
0.2%
2022 CWE-122 1 PoC

mruby is vulnerable to Heap-based Buffer Overflow

CVE-2022-4801
usememos/memos General
8.2
HIGH
EPSS
0.2%
2022 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-2306
heroiclabs/nakama General
8.2
HIGH
EPSS
0.2%
2022 CWE-613 1 PoC

Old session tokens can be used to authenticate to the application and send authenticated requests.

CVE-2022-0951
star7th/showdoc Web
8.2
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

File Upload Restriction Bypass leading to Stored XSS Vulnerability in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-35887
iota All-In-One Security Kit Web
8.2
HIGH
EPSS
1.6%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` HTTP parameter, as used within the `/action/wirelessConnect` handler.

CVE-2022-31705
VMware ESXi, VMware Workstation Pro / Player, VMware Fusion Pro / Fusion (Fusion), VMware Cloud Foundation Cloud
8.2
HIGH
EPSS
2.5%
2022 1 PoC

VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed.

CVE-2022-41966
xstream General
8.2
HIGH
EPSS
2.5%
2022 CWE-120 1 PoC

XStream serializes Java objects to XML and back again. Versions prior to 1.4.20 may allow a remote attacker to terminate the application with a stack overflow error, resulting in a denial of service only via manipulation the processed input stream. The attack uses the hash code implementation for collections and maps to force recursive hash calculation causing a stack overflow. This issue is patched in version 1.4.20 which handles the stack overflow and raises an InputManipulationException instead. A potential workaround for users who only use HashMap or HashSet and whose XML refers these only

CVE-2022-21513
Sun ZFS Storage Appliance Kit (AK) Software Database
8.2
HIGH
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Core). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. While the vulnerability is in Oracle ZFS Storage Appliance Kit, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit. CVSS 3.1 Base Score 8.2 (C

CVE-2022-35884
iota All-In-One Security Kit Web
8.2
HIGH
EPSS
1.6%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability arises from format string injection via the `ssid_hex` HTTP parameter, as used within the `/action/wirelessConnect` handler.

CVE-2022-35877
iota All-In-One Security Kit General
8.2
HIGH
EPSS
0.5%
2022 CWE-134 1 PoC

Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and then execute an XCMD to trigger these vulnerabilities.This vulnerability arises from format string injection via the `default_key_id` configuration parameter, as used within the `testWifiAP` XCMD handler