14993 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-20473
Android General
9.8
CRITICAL
EPSS
50.9%
2022 1 PoC

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239267173

CVE-2022-44832
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2022 1 PoC

D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

CVE-2022-41352
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2022 8 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

CVE-2022-40021
Software Genérico General
9.8
CRITICAL
EPSS
3.3%
2022 1 PoC

QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.

CVE-2022-45481
Lazy Mouse General
9.8
CRITICAL
EPSS
2.6%
2022 CWE-306 1 PoC

The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-44202
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

CVE-2022-2068
OpenSSL General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbi

CVE-2022-44250
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

CVE-2022-26143
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.1%
2022 2 PoCs

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVE-2022-44000
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

CVE-2022-37055
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
80.5%
2022 1 PoC

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

CVE-2022-47758
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 2 PoCs

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

CVE-2022-34270
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

CVE-2022-1440
yarkeev/git-interface General
9.8
CRITICAL
EPSS
8.5%
2022 CWE-78 1 PoC

Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.

CVE-2022-42233
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
84.4%
2022 0 PoCs

Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

CVE-2022-47117
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security parameter at /goform/WifiBasicSet.

CVE-2022-22822
Software Genérico General
9.8
CRITICAL
EPSS
1.3%
2022 1 PoC

addBinding in xmlparse.c in Expat (aka libexpat) before 2.4.3 has an integer overflow.

CVE-2022-47128
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey2 parameter at /goform/WifiBasicSet.

CVE-2022-29889
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
1.1%
2022 CWE-798 1 PoC

A hard-coded password vulnerability exists in the telnet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. Use of a hard-coded root password can lead to arbitrary command execution. An attacker can authenticate with hard-coded credentials to trigger this vulnerability.

CVE-2022-44001
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. User authentication for accessing the CORBA back-end services can be bypassed.