9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-6209
SAP Disclosure Management General
7.2
HIGH
EPSS
0.4%
2020 1 PoC

SAP Disclosure Management, version 10.1, does not perform necessary authorization checks for an authenticated user, allowing access to administration accounts by a user with no roles, leading to Missing Authorization Check.

CVE-2020-11252
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking General
7.2
HIGH
EPSS
0.0%
2020 1 PoC

Trustzone initialization code will disable xPU`s when memory dumps are enabled and lead to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

CVE-2020-2038
PAN-OS General
7.2
HIGH
EPSS
87.3%
2020 CWE-78 5 PoCs

An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.1 versions earlier than 9.1.4; PAN-OS 10.0 versions earlier than 10.0.1.

CVE-2016-11021
🔥 KEV Software Genérico General
7.2
HIGH
EPSS
91.3%
2016 1 PoC

setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in the SystemCommand parameter.

CVE-2018-4021
Netgate pfSense General
7.2
HIGH
EPSS
84.8%
2018 1 PoC

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_battery_mode` POST parameter.

CVE-2018-4019
Netgate pfSense General
7.2
HIGH
EPSS
84.2%
2018 1 PoC

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_normal_mode` parameter.

CVE-2018-9276
🔥 KEV Software Genérico General
7.2
HIGH
EPSS
87.5%
2018 7 PoCs

An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

CVE-2018-4020
Netgate pfSense General
7.2
HIGH
EPSS
84.2%
2018 1 PoC

An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this and gain the ability to execute arbitrary commands on the system. An attacker needs to be able to send authenticated POST requests to the administration web interface. Command injection is possible in the `powerd_ac_mode` POST parameter parameter.

CVE-2022-40924
Software Genérico General
7.2
HIGH
EPSS
0.4%
2022 1 PoC

Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_animal" file of the "Animals" module in the background management system.

CVE-2022-41002
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no icmp check link WORD destination WORD interval <1-255> retries <1-255> description (WORD|null)' command template.

CVE-2022-40992
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no firmwall domain WORD description (WORD|null)' command template.

CVE-2022-41000
QUARTZ-GOLD General
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no gre index <1-8> tunnel A.B.C.D source (A.B.C.D|null) dest A.B.C.D keepalive (on|off) interval (<0-255>|null) retry (<0-255>|null) description (WORD|null)' command template.

CVE-2022-42201
Software Genérico General
7.2
HIGH
EPSS
0.4%
2022 1 PoC

Simple Exam Reviewer Management System v1.0 is vulnerable to Insecure file upload.

CVE-2022-1033
crater-invoice/crater General
7.2
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository crater-invoice/crater prior to 6.0.6.

CVE-2022-0819
dolibarr/dolibarr General
7.2
HIGH
EPSS
1.7%
2022 CWE-94 1 PoC

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

CVE-2022-42140
Software Genérico General
7.2
HIGH
EPSS
9.6%
2022 1 PoC

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

CVE-2022-27925
🔥 KEV Software Genérico General
7.2
HIGH
EPSS
94.3%
2022 16 PoCs

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.