818 vulnerabilidades · Networking Orden: CVSS EPSS Año ID
CVE-2022-0342
USG/ZyWALL series firmware Networking ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2022 CWE-287 0 PoCs

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

CVE-2022-44197
Software Genérico Networking
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_server_ip.

CVE-2022-44198
Software Genérico Networking
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter openvpn_push1.

CVE-2022-1388
🔥 KEV BIG-IP Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-306 87 PoCs

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-31937
Software Genérico Web Networking
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

CVE-2022-24706
🔥 KEV Apache CouchDB Web Networking
9.8
CRITICAL
EPSS
94.4%
2022 CWE-1188 9 PoCs

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVE-2022-30525
🔥 KEV USG FLEX 100(W) firmware Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 CWE-78 23 PoCs

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execut

CVE-2022-45551
Software Genérico Networking
9.8
CRITICAL
EPSS
3.1%
2022 1 PoC

An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.

CVE-2022-44196
Software Genérico Networking
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

CVE-2022-37235
Software Genérico Networking
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

CVE-2022-45047
Apache MINA SSHD Web Networking
9.8
CRITICAL
EPSS
5.7%
2022 CWE-502 1 PoC

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CVE-2022-46637
Software Genérico Networking
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.

CVE-2022-3236
🔥 KEV Sophos Firewall Networking ⚡ nuclei
9.8
CRITICAL
EPSS
92.8%
2022 0 PoCs

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-40684
🔥 KEV Fortinet FortiOS, FortiProxy, FortiSwitchManager Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 27 PoCs

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CVE-2022-4873
NF20 Networking
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

CVE-2022-39952
FortiNAC Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2022 CWE-73 4 PoCs

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

CVE-2023-34992
FortiSIEM Web Networking
9.7
CRITICAL
EPSS
75.9%
2023 CWE-78 2 PoCs

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

CVE-2024-23108
FortiSIEM Web Networking
9.7
CRITICAL
EPSS
90.4%
2024 CWE-78 2 PoCs

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.

CVE-2025-67511
cai Networking
9.7
CRITICAL
EPSS
0.1%
2025 CWE-77 1 PoC

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automation. Versions 0.5.9 and below are vulnerable to Command Injection through the run_ssh_command_with_credentials() function, which is available to AI agents. Only password and command inputs are escaped in run_ssh_command_with_credentials to prevent shell injection; while username, host and port values are injectable. This issue does not have a fix at the time of publication.

CVE-2023-34990
FortiWLM Networking ⚡ nuclei
9.6
CRITICAL
EPSS
72.9%
2023 CWE-23 0 PoCs

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted web requests.