14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-42149
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
42.8%
2022 0 PoCs

kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

CVE-2022-45699
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2022 1 PoC

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.

CVE-2022-46280
Open Babel General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-824 1 PoC

A use of uninitialized pointer vulnerability exists in the PQS format pFormat functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-24086
🔥 KEV Magento Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2022 CWE-20 15 PoCs

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

CVE-2022-45717
Software Genérico General
9.8
CRITICAL
EPSS
5.3%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.

CVE-2022-41793
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-120 2 PoCs

An out-of-bounds write vulnerability exists in the CSR format title functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-46600
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_24g function.

CVE-2022-26138
🔥 KEV Questions For Confluence General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 CWE-798 5 PoCs

The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.

CVE-2022-2242
SystemSoftware V/KSS General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-306 1 PoC

The KUKA SystemSoftware V/KSS in versions prior to 8.6.5 is prone to improper access control as an unauthorized attacker can directly read and write robot configurations when access control is not available or not enabled (default).

CVE-2022-46292
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC file format, inside the Unit Cell Translation section

CVE-2022-42885
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-824 1 PoC

A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-35405
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.2%
2022 3 PoCs

Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code execution. (This also affects ManageEngine Access Manager Plus before 4303 with authentication.)

CVE-2022-37298
Software Genérico General
9.8
CRITICAL
EPSS
16.3%
2022 1 PoC

Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server.

CVE-2022-43003
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.

CVE-2022-45062
Software Genérico General
9.8
CRITICAL
EPSS
3.5%
2022 2 PoCs

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

CVE-2022-46590
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.

CVE-2022-45718
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.

CVE-2022-41991
QUARTZ-GOLD General
9.8
CRITICAL
EPSS
0.5%
2022 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2022-44928
Software Genérico General
9.8
CRITICAL
EPSS
15.2%
2022 1 PoC

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVE-2022-41138
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.