1389 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-1986
gogs/gogs General
10.0
CRITICAL
EPSS
9.2%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

CVE-2022-30541
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
1.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-33194
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
3.6%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_Key` and `WL_DefaultKeyID` configuration values in the function located at offset `0x1c7d28` of firmware 6.9Z , and even more specifically on the command execution occuring at offset `0x1c7f6c`.

CVE-2022-27593
🔥 KEV Photo Station General ⚡ nuclei
10.0
CRITICAL
EPSS
93.1%
2022 CWE-610 0 PoCs

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-3167
ikus060/rdiffweb General
10.0
CRITICAL
EPSS
0.4%
2022 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository ikus060/rdiffweb prior to 2.4.1.

CVE-2022-33193
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
3.6%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_WPAPSK` configuration value in the function located at offset `0x1c7d28` of firmware 6.9Z.

CVE-2022-2310
Skyhigh Secure Web Gateway (SWG) General
10.0
CRITICAL
EPSS
1.4%
2022 CWE-290 1 PoC

An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super u

CVE-2022-36067
vm2 General
10.0
CRITICAL
EPSS
82.5%
2022 CWE-913 3 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

CVE-2022-43604
OpENer General
10.0
CRITICAL
EPSS
7.6%
2022 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVE-2022-2734
openemr/openemr General
10.0
CRITICAL
EPSS
1.0%
2022 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-31491
Software Genérico General
10.0
CRITICAL
EPSS
0.2%
2022 1 PoC

Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS shutting down. An unauthenticated attacker can use this to run arbitrary code immediately regardless of any managed UPS state or presence.

CVE-2022-21941
iSTAR Ultra General
10.0
CRITICAL
EPSS
19.7%
2022 CWE-77 1 PoC

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

CVE-2022-32773
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
4.8%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-1992
gogs/gogs General
10.0
CRITICAL
EPSS
1.7%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

CVE-2022-32454
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
5.0%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to remote code execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-43605
OpENer General
10.0
CRITICAL
EPSS
5.5%
2022 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVE-2022-33195
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
4.8%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_DefaultKeyID` in the function located at offset `0x1c7d28` of firmware 6.9Z, and even more specifically on the command execution occuring at offset `0x1c7fac`.

CVE-2022-33189
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
1.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-33192
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
3.6%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_SSID` and `WL_SSID_HEX` configuration values in the function at offset `0x1c7d28` of firmware 6.9Z.