14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-34850
R1510 General
9.1
CRITICAL
EPSS
1.4%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-4802
usememos/memos General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-26851
PowerScale OneFS General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-330 1 PoC

Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

CVE-2022-45891
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).

CVE-2022-1034
star7th/showdoc General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-434 1 PoC

There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-44900
Software Genérico General
9.1
CRITICAL
EPSS
28.6%
2022 2 PoCs

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.

CVE-2022-2339
nocodb/nocodb General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-918 1 PoC

With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.

CVE-2022-32585
R1510 General
9.1
CRITICAL
EPSS
0.7%
2022 CWE-489 1 PoC

A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-2073
getgrav/grav General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-94 1 PoC

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

CVE-2022-33150
R1510 General
9.1
CRITICAL
EPSS
1.2%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-28223
Software Genérico General
9.1
CRITICAL
EPSS
0.8%
2022 1 PoC

Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

CVE-2022-24856
flyteconsole General ⚡ nuclei
9.1
CRITICAL
EPSS
81.9%
2022 CWE-918 0 PoCs

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a wor

CVE-2022-23131
🔥 KEV Frontend General ⚡ nuclei
9.1
CRITICAL
EPSS
94.0%
2022 CWE-290 22 PoCs

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

CVE-2022-0767
janeczku/calibre-web General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.

CVE-2022-1411
yetiforcecompany/yetiforcecrm General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

CVE-2022-2064
nocodb/nocodb General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-29951
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2022 1 PoC

JTEKT TOYOPUC PLCs through 2022-04-29 mishandle authentication. They utilize the CMPLink/TCP protocol (configurable on ports 1024-65534 on either TCP or UDP) for a wide variety of engineering purposes such as starting and stopping the PLC, downloading and uploading projects, and changing configuration settings. This protocol does not have any authentication features, allowing any attacker capable of communicating with the port in question to invoke (a subset of) desired functionality.

CVE-2022-32765
R1510 General
9.1
CRITICAL
EPSS
1.3%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-39811
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2022 1 PoC

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to view pages that are not allowed, and modify the system configuration, bypassing all controls (without checking for user identity).

CVE-2022-1811
publify/publify General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.