2350 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-45716
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.

CVE-2022-39989
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.

CVE-2022-44804
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

CVE-2022-47123
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.

CVE-2022-4797
usememos/memos General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-37454
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

CVE-2022-46586
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function.

CVE-2022-44929
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

CVE-2022-23219
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

CVE-2022-48108
Software Genérico General
9.8
CRITICAL
EPSS
21.9%
2022 1 PoC

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-45896
Software Genérico General
9.8
CRITICAL
EPSS
3.0%
2022 1 PoC

Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

CVE-2022-45479
PC Keyboard WiFi & Bluetooth General
9.8
CRITICAL
EPSS
3.6%
2022 CWE-306 1 PoC

PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-44004
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.

CVE-2022-48107
Software Genérico General
9.8
CRITICAL
EPSS
21.9%
2022 1 PoC

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-44201
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVE-2022-44283
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

CVE-2022-31706
vRealize Log Insight (vRLI) General ⚡ nuclei
9.8
CRITICAL
EPSS
90.2%
2022 1 PoC

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

CVE-2022-46583
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

CVE-2022-22954
🔥 KEV VMware Workspace ONE Access and Identity Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 36 PoCs

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVE-2022-35244
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
0.7%
2022 CWE-134 1 PoC

A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.