3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-45718
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formIPMacBindAdd function.

CVE-2022-45711
Software Genérico General
9.8
CRITICAL
EPSS
15.8%
2022 1 PoC

IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the hostname parameter in the formSetNetCheckTools function.

CVE-2022-44255
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

CVE-2022-1715
neorazorx/facturascripts General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-1125 1 PoC

Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.

CVE-2022-44190
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

CVE-2022-36231
Software Genérico General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

CVE-2022-47121
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

CVE-2022-42233
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
84.4%
2022 0 PoCs

Tenda 11N with firmware version V5.07.33_cn suffers from an Authentication Bypass vulnerability.

CVE-2022-46581
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.

CVE-2022-46599
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.

CVE-2022-45712
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.

CVE-2022-23218
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

CVE-2022-47035
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

Buffer Overflow Vulnerability in D-Link DIR-825 v1.33.0.44ebdd4-embedded and below allows attacker to execute arbitrary code via the GetConfig method to the /CPE endpoint.

CVE-2022-46590
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_rsname parameter in the tools_netstat (sub_41E730) function.

CVE-2022-44191
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

CVE-2022-25235
Software Genérico General
9.8
CRITICAL
EPSS
13.3%
2022 2 PoCs

xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

CVE-2022-4851
usememos/memos General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-229 1 PoC

Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1292
OpenSSL General
9.8
CRITICAL
EPSS
37.8%
2022 8 PoCs

The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbitrary commands with the privileges of the script. Use of the c_rehash script is considered obsolete and should be replaced by the OpenSSL rehash command line tool. Fixed in OpenSSL 3.0.3 (Affected 3.0.0,3.0.1,3.0.2). Fixed in OpenSSL 1.1.1o (Affected 1.1.1-1.1.1n). Fixed in OpenSSL 1.0.2ze (Affected 1.0.2-1.0.2zd).

CVE-2022-40434
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.

CVE-2022-45062
Software Genérico General
9.8
CRITICAL
EPSS
3.5%
2022 2 PoCs

In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.