7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-41999
OpenImageIO General
7.5
HIGH
EPSS
0.3%
2022 CWE-476 1 PoC

A denial of service vulnerability exists in the DDS native tile reading functionality of OpenImageIO Project OpenImageIO v2.3.19.0 and v2.4.4.2. A specially-crafted .dds can lead to denial of service. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-48483
Software Genérico Windows
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download directory traversal in conjunction with a path component that has a drive letter and uses backslash characters. NOTE: this issue exists because of an incomplete fix for CVE-2022-28005.

CVE-2022-25892
muhammara General
7.5
HIGH
EPSS
2.6%
2022 2 PoCs

The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.

CVE-2022-44216
Software Genérico General
7.5
HIGH
EPSS
0.2%
2022 1 PoC

Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password.

CVE-2022-27782
https://github.com/curl/curl Web Networking
7.5
HIGH
EPSS
0.5%
2022 CWE-840 1 PoC

libcurl would reuse a previously created connection even when a TLS or SSHrelated option had been changed that should have prohibited reuse.libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse if one of them matches the setup. However, several TLS andSSH settings were left out from the configuration match checks, making themmatch too easily.

CVE-2022-47717
Software Genérico General
7.5
HIGH
EPSS
0.3%
2022 1 PoC

Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).

CVE-2022-24713
regex Web
7.5
HIGH
EPSS
10.4%
2022 CWE-400 2 PoCs

regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This ma

CVE-2022-46463
Software Genérico DevOps
7.5
HIGH
EPSS
76.9%
2022 3 PoCs

An access control issue in Harbor v1.X.X to v2.5.3 allows attackers to access public and private image repositories without authentication. NOTE: the vendor's position is that this "is clearly described in the documentation as a feature."

CVE-2022-46355
SCALANCE X204RNA (HSR) Web
7.5
HIGH
EPSS
0.4%
2022 CWE-200 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The affected products are vulnerable to an "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability by leaking sensitive data in the HTTP Referer.

CVE-2022-44167
Software Genérico General
7.5
HIGH
EPSS
0.4%
2022 1 PoC

Tenda AC15 V15.03.05.18 is avulnerable to Buffer Overflow via function formSetPPTPServer.

CVE-2022-4636
KVM ACR1020A-T General
7.5
HIGH
EPSS
0.3%
2022 CWE-22 1 PoC

Black Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to path traversal, which may allow an attacker to steal user credentials and other sensitive information through local file inclusion.

CVE-2022-21266
Communications Billing and Revenue Management Web Database
7.5
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Pipeline Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 7.5 (Confidenti

CVE-2022-24400
TETRA Standard General
7.5
HIGH
EPSS
0.2%
2022 CWE-807 1 PoC

A flaw in the TETRA authentication procecure allows a MITM adversary that can predict the MS challenge RAND2 to set session key DCK to zero.

CVE-2022-2591
FLEX-1085 General
7.5
HIGH
EPSS
3.8%
2022 CWE-404 1 PoC

A vulnerability classified as critical has been found in TEM FLEX-1085 1.6.0. Affected is an unknown function of the file /sistema/flash/reboot. The manipulation leads to denial of service. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2022-30746
Smart Things Web
7.5
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

Missing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript interface API.

CVE-2022-25940
lite-server Web
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

CVE-2022-21251
Installed Base Web Database
7.5
HIGH
EPSS
2.0%
2022 1 PoC

Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Instance Main). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Installed Base. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-50978
VibroLine VLX1 HD 5.0 General
7.5
HIGH
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP).

CVE-2022-21570
Coherence Database
7.5
HIGH
EPSS
1.1%
2022 1 PoC

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 3.7.1.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

CVE-2022-24279
madlib-object-utils Web
7.5
HIGH
EPSS
0.5%
2022 2 PoCs

The package madlib-object-utils before 0.1.8 are vulnerable to Prototype Pollution via the setValue method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix of [CVE-2020-7701](https://security.snyk.io/vuln/SNYK-JS-MADLIBOBJECTUTILS-598676)