In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
CVE-2022-22947
🔥 KEV
Spring Cloud Gateway
Web
Cloud
⚡ nuclei
10.0
CRITICAL
EPSS
94.5%
CVE-2022-22963
🔥 KEV
Spring Cloud Function
Web
Cloud
⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CVE-2022-31678
VMware Cloud Foundation (NSX-V)
Cloud
⚡ nuclei
9.1
CRITICAL
EPSS
86.0%
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.
CVE-2022-29383
Software Genérico
Networking
Database
Cloud
⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.