3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-3993
kareadita/kavita General
9.4
CRITICAL
EPSS
1.4%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository kareadita/kavita prior to 0.6.0.3.

CVE-2022-4980
Crypto Application Server (CAS) General
9.3
CRITICAL
EPSS
0.8%
2022 CWE-306 2 PoCs

General Bytes Crypto Application Server (CAS) beginning with version 20201208 prior to 20220531.38 (backport) and 20220725.22 (mainline) contains an authentication bypass in the admin web interface. An unauthenticated attacker could invoke the same URL used by the product's default-installation / first-admin creation page and create a new administrative account remotely. By gaining admin privileges, the attacker can change the ATM configuration resulting in redirected funds. Public vendor advisories and multiple independent writeups describe the vulnerability as a call to the page used for ini

CVE-2022-1543
erudika/scoold General
9.3
CRITICAL
EPSS
0.4%
2022 CWE-130 1 PoC

Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.

CVE-2022-50691
MiniDVBLinux General
9.3
CRITICAL
EPSS
0.4%
2022 CWE-78 1 PoC

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.

CVE-2022-0990
janeczku/calibre-web General
9.3
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

CVE-2022-27660
LinkHub Mesh Wifi General
9.3
CRITICAL
EPSS
0.5%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-27185
LinkHub Mesh Wifi General
9.3
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_master_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-1212
mruby/mruby General
9.3
CRITICAL
EPSS
0.9%
2022 CWE-416 1 PoC

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-41559
TIBCO Nimbus General
9.3
CRITICAL
EPSS
1.0%
2022 1 PoC

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: version 10.5.0.

CVE-2022-50796
Impact/Pulse/First General
9.3
CRITICAL
EPSS
1.1%
2022 CWE-22 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.

CVE-2022-50919
Tdarr General
9.3
CRITICAL
EPSS
1.5%
2022 CWE-78 1 PoC

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.

CVE-2022-4978
Remote Control Collection Server General
9.3
CRITICAL
EPSS
32.4%
2022 CWE-306 1 PoC

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same network can issue a sequence of keystroke commands to launch a system shell and execute arbitrary commands, resulting in full system compromise.

CVE-2022-1996
emicklei/go-restful General
9.3
CRITICAL
EPSS
1.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVE-2022-21817
Software Genérico General
9.3
CRITICAL
EPSS
0.9%
2022 1 PoC

NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.

CVE-2022-32765
R1510 General
9.1
CRITICAL
EPSS
1.3%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-42905
Software Genérico General
9.1
CRITICAL
EPSS
6.1%
2022 3 PoCs

In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)

CVE-2022-1399
CMDB General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-88 1 PoC

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-45891
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).

CVE-2022-0913
microweber/microweber General
9.1
CRITICAL
EPSS
0.8%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-45796
SHARP multifunction printers General
9.1
CRITICAL
EPSS
2.5%
2022 CWE-77 1 PoC

Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional System (Monochrome) 200 or earlier, 211 or earlier, 102 or earlier, 453 or earlier, 400 or earlier, 202 or earlier, 602 or earlier, 500 or earlier, 401 or earlier allows remote attackers to execute arbitrary commands via unspecified vectors.