CVE-2023-48427
- EPSS 0.08%
- Published 12.12.2023 12:15:14
- Last modified 21.11.2024 08:31:42
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected products do not properly validate the certificate of the configured UMC server. This could allow an attacker to intercept credentials that are sent to the U...
CVE-2022-45094
- EPSS 0.79%
- Published 10.01.2023 12:15:23
- Last modified 21.11.2024 07:28:46
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhcpd configur...
CVE-2022-45093
- EPSS 1.79%
- Published 10.01.2023 12:15:23
- Last modified 21.11.2024 07:28:46
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product as well as with access to the SFTP server of the affected ...
CVE-2022-45092
- EPSS 21.76%
- Published 10.01.2023 12:15:23
- Last modified 21.11.2024 07:28:45
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially read and write arbitrary files from and...
CVE-2022-35256
- EPSS 4.58%
- Published 05.12.2022 22:15:10
- Last modified 24.04.2025 14:15:32
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
CVE-2022-35255
- EPSS 1.39%
- Published 05.12.2022 22:15:10
- Last modified 24.04.2025 14:15:32
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, i...
CVE-2022-32213
- EPSS 89.07%
- Published 14.07.2022 15:15:08
- Last modified 21.11.2024 07:05:56
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
CVE-2022-32222
- EPSS 0.42%
- Published 14.07.2022 15:15:08
- Last modified 21.11.2024 07:05:57
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in ve...
CVE-2022-32215
- EPSS 88.11%
- Published 14.07.2022 15:15:08
- Last modified 21.11.2024 07:05:56
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
CVE-2022-32212
- EPSS 0.08%
- Published 14.07.2022 15:15:08
- Last modified 21.11.2024 07:05:56
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making D...