2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-44801
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2022 1 PoC

D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

CVE-2022-47873
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2022 2 PoCs

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVE-2022-46585
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.

CVE-2022-47767
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.

CVE-2022-45709
Software Genérico General
9.8
CRITICAL
EPSS
5.3%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

CVE-2022-2595
kromitgmbh/titra General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.

CVE-2022-43999
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

CVE-2022-39184
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.

CVE-2022-36934
WhatsApp for iOS General
9.8
CRITICAL
EPSS
12.7%
2022 CWE-122 1 PoC

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVE-2022-41639
OpenImageIO General
9.8
CRITICAL
EPSS
0.8%
2022 CWE-122 1 PoC

A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-47036
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.

CVE-2022-36231
Software Genérico General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

CVE-2022-41220
Software Genérico General
9.8
CRITICAL
EPSS
12.6%
2022 1 PoC

md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

CVE-2022-46599
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.

CVE-2022-23218
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

CVE-2022-43000
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

CVE-2022-47121
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

CVE-2022-46294
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC Cartesian file format

CVE-2022-1715
neorazorx/facturascripts General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-1125 1 PoC

Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

CVE-2022-3422
tooljet/tooljet General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-269 1 PoC

Account Takeover :: when see the info i can see the hash pass i can creaked it ............... Account Takeover :: when see the info i can see the forgot_password_token the hacker can send the request and changed the pass