3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-39185
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

CVE-2022-42492
QUARTZ-GOLD General
9.8
CRITICAL
EPSS
3.8%
2022 CWE-78 1 PoC

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's DOWNLOAD_AD command.

CVE-2022-46580
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.

CVE-2022-43999
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

CVE-2022-47036
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.

CVE-2022-37298
Software Genérico General
9.8
CRITICAL
EPSS
16.3%
2022 1 PoC

Shinken Solutions Shinken Monitoring Version 2.4.3 affected is vulnerable to Incorrect Access Control. The SafeUnpickler class found in shinken/safepickle.py implements a weak authentication scheme when unserializing objects passed from monitoring nodes to the Shinken monitoring server.

CVE-2022-46581
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.

CVE-2022-45477
Telepad General
9.8
CRITICAL
EPSS
9.5%
2022 CWE-306 1 PoC

Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-44006
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVE-2022-42885
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-824 1 PoC

A use of uninitialized pointer vulnerability exists in the GRO format res functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-46292
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC file format, inside the Unit Cell Translation section

CVE-2022-45637
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVE-2022-40055
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

CVE-2022-43003
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setRepeaterSecurity function.

CVE-2022-39073
MF286R General
9.8
CRITICAL
EPSS
17.6%
2022 1 PoC

There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.

CVE-2022-3268
ikus060/minarca General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

CVE-2022-4851
usememos/memos General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-229 1 PoC

Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-36231
Software Genérico General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

CVE-2022-46601
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.

CVE-2022-45711
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2022 1 PoC

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.