3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-37055
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
80.5%
2022 1 PoC

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

CVE-2022-44000
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

CVE-2022-25767
com.bstek.ureport:ureport2-console General
9.8
CRITICAL
EPSS
3.1%
2022 1 PoC

All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

CVE-2022-26143
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.1%
2022 2 PoCs

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVE-2022-46583
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

CVE-2022-46295
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the Gaussian file format

CVE-2022-44832
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2022 1 PoC

D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

CVE-2022-47035
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

CVE-2022-48107
Software Genérico General
9.8
CRITICAL
EPSS
21.9%
2022 1 PoC

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-44201
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVE-2022-44283
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

CVE-2022-26318
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
92.2%
2022 5 PoCs

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVE-2022-32588
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the PICT parsing pctwread_14841 functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-38580
Software Genérico General
9.8
CRITICAL
EPSS
48.8%
2022 1 PoC

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

CVE-2022-48113
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2022 1 PoC

A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

CVE-2022-25894
com.bstek.uflo:uflo-core General
9.8
CRITICAL
EPSS
3.7%
2022 CWE-94 1 PoC

All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.

CVE-2022-38143
OpenImageIO General
9.8
CRITICAL
EPSS
0.7%
2022 CWE-123 1 PoC

A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-41837
OpenImageIO General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-562 1 PoC

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-44202
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

CVE-2022-46581
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.