3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-2631
tooljet/tooljet General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

CVE-2022-43001
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

CVE-2022-45699
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2022 1 PoC

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.

CVE-2022-2818
cockpit-hq/cockpit General
9.8
CRITICAL
EPSS
1.5%
2022 CWE-212 1 PoC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

CVE-2022-44006
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVE-2022-46295
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the Gaussian file format

CVE-2022-44194
Software Genérico General
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameters apmode_dns1_pri and apmode_dns1_sec.

CVE-2022-34668
NVIDIA FLARE General
9.8
CRITICAL
EPSS
22.4%
2022 CWE-502 1 PoC

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVE-2022-45711
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2022 1 PoC

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

CVE-2022-39184
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.

CVE-2022-39073
MF286R General
9.8
CRITICAL
EPSS
17.6%
2022 1 PoC

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

CVE-2022-45707
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.

CVE-2022-50981
VibroLine VLX1 HD 5.0 General
9.8
CRITICAL
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

CVE-2022-42842
macOS General
9.8
CRITICAL
EPSS
4.1%
2022 6 PoCs

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVE-2022-2821
namelessmc/nameless General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-304 1 PoC

Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

CVE-2022-42837
macOS General
9.8
CRITICAL
EPSS
5.9%
2022 4 PoCs

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.

CVE-2022-2068
OpenSSL General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbi

CVE-2022-44806
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

CVE-2022-21165
font-converter General
9.8
CRITICAL
EPSS
2.6%
2022 1 PoC

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

CVE-2022-4797
usememos/memos General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.