14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-26808
SAP AS ABAP(DMIS) General
9.1
CRITICAL
EPSS
3.7%
2020 2 PoCs

SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code into function module leading to code injection that can be executed in the application which affects the confidentiality, availability and integrity of the application.

CVE-2016-8721
Moxa AWK-3131A WAP General
9.1
CRITICAL
EPSS
1.0%
2016 2 PoCs

An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely.

CVE-2018-12465
Secure Messaging Gateway General
9.1
CRITICAL
EPSS
82.2%
2018 CWE-77 1 PoC

An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).

CVE-2018-1000301
Software Genérico General
9.1
CRITICAL
EPSS
2.7%
2018 4 PoCs

curl version curl 7.20.0 to and including curl 7.59.0 contains a CWE-126: Buffer Over-read vulnerability in denial of service that can result in curl can be tricked into reading data beyond the end of a heap based buffer used to store downloaded RTSP content.. This vulnerability appears to have been fixed in curl < 7.20.0 and curl >= 7.60.0.

CVE-2022-2062
nocodb/nocodb General
9.1
CRITICAL
EPSS
1.3%
2022 CWE-209 1 PoC

Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-1380
snipe/snipe-it General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-79 1 PoC

Stored Cross Site Scripting vulnerability in Item name parameter in GitHub repository snipe/snipe-it prior to v5.4.3. The vulnerability is capable of stolen the user Cookie.

CVE-2022-0742
Kernel General
9.1
CRITICAL
EPSS
2.2%
2022 CWE-275 1 PoC

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

CVE-2022-1931
polonel/trudesk General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-821 1 PoC

Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-26082
OAS Platform General
9.1
CRITICAL
EPSS
2.7%
2022 CWE-306 1 PoC

A file write vulnerability exists in the OAS Engine SecureTransferFiles functionality of Open Automation Software OAS Platform V16.00.0112. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-0913
microweber/microweber General
9.1
CRITICAL
EPSS
0.8%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-1399
CMDB General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-88 1 PoC

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-2626
hestiacp/hestiacp General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-266 1 PoC

Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.

CVE-2022-21723
pjproject General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-125 1 PoC

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.

CVE-2022-1947
polonel/trudesk General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-480 1 PoC

Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-42905
Software Genérico General
9.1
CRITICAL
EPSS
6.1%
2022 3 PoCs

In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)

CVE-2022-39227
python-jwt General
9.1
CRITICAL
EPSS
71.3%
2022 CWE-290 3 PoCs

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVE-2022-0482
alextselegidis/easyappointments General ⚡ nuclei
9.1
CRITICAL
EPSS
90.8%
2022 CWE-359 4 PoCs

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

CVE-2022-45796
SHARP multifunction printers General
9.1
CRITICAL
EPSS
2.5%
2022 CWE-77 1 PoC

Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional System (Monochrome) 200 or earlier, 211 or earlier, 102 or earlier, 453 or earlier, 400 or earlier, 202 or earlier, 602 or earlier, 500 or earlier, 401 or earlier allows remote attackers to execute arbitrary commands via unspecified vectors.

CVE-2022-36323
RUGGEDCOM RM1224 LTE(4G) EU General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-74 1 PoC

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

CVE-2022-0724
microweber/microweber General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-922 1 PoC

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.