9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-21225
Intel(R) Data Center Manager software General
8.0
HIGH
EPSS
1.5%
2022 2 PoCs

Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-39882
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2022 CWE-787 1 PoC

Heap overflow vulnerability in sflacf_fal_bytes_peek function in libsmat.so library prior to SMR Nov-2022 Release 1 allows local attacker to execute arbitrary code.

CVE-2022-2287
vim/vim General
8.0
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVE-2022-1544
luyadev/yii-helpers General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

CVE-2022-0868
medialize/uri.js General
8.0
HIGH
EPSS
0.3%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

CVE-2022-2487
WN535K2 General ⚡ nuclei
8.0
HIGH
EPSS
93.1%
2022 CWE-78 1 PoC

A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.

CVE-2022-2486
WN535K2 General ⚡ nuclei
8.0
HIGH
EPSS
91.0%
2022 CWE-78 1 PoC

A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.

CVE-2022-21934
Metasys ADS/ADX/OAS server General
8.0
HIGH
EPSS
0.3%
2022 CWE-620 1 PoC

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.

CVE-2022-2027
kromitgmbh/titra General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVE-2022-1410
CMDB General
8.0
HIGH
EPSS
1.2%
2022 CWE-78 1 PoC

OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-0155
follow-redirects/follow-redirects General
8.0
HIGH
EPSS
1.3%
2022 CWE-359 1 PoC

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVE-2022-4815
Pentaho Business Analytics Server General
8.0
HIGH
EPSS
0.5%
2022 CWE-502 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 

CVE-2022-21668
pipenv General
8.0
HIGH
EPSS
1.5%
2022 CWE-20 1 PoC

pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which will cause victims who use pipenv to install the requirements file to download dependencies from a package index server controlled by the attacker. By embedding malicious code in packages served from their malicious index server, the attacker can trigger arbitrary remote code execution (RCE) on the victims' systems. If a

CVE-2022-39852
Samsung Mobile Devices General
8.0
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

A heap-based overflow vulnerability in makeContactAGIF in libagifencoder.quram.so library prior to SMR Oct-2022 Release 1 allows attacker to perform code execution.

CVE-2026-4802
Red Hat Enterprise Linux 10 General
8.0
HIGH
EPSS
0.2%
2026 CWE-78 1 PoC

A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.

CVE-2018-21101
Software Genérico General
8.0
HIGH
EPSS
0.2%
2018 1 PoC

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

CVE-2023-30709
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.1%
2023 1 PoC

Improper access control in Dual Messenger prior to SMR Sep-2023 Release 1 allows local attackers launch activity with system privilege.

CVE-2023-21477
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2023 1 PoC

Access of Memory Location After End of Buffer vulnerability in TIGERF trustlet prior to SMR Apr-2023 Release 1 allows local attackers to access protected data.

CVE-2023-4876
hamza417/inure General
7.9
HIGH
EPSS
0.1%
2023 CWE-200 1 PoC

Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository hamza417/inure prior to build92.

CVE-2024-20874
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in SmartManagerCN prior to SMR Jun-2024 Release 1 allows local attackers to launch privileged activities.