170 vulnerabilidades · Networking · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-39986
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
93.1%
2022 7 PoCs

A Command injection vulnerability in RaspAP 2.8.0 thru 2.8.7 allows unauthenticated attackers to execute arbitrary commands via the cfg_id parameter in /ajax/openvpn/activate_ovpncfg.php and /ajax/openvpn/del_ovpncfg.php.

CVE-2022-29014
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
65.9%
2022 2 PoCs

A local file inclusion vulnerability in Razer Sila Gaming Router v2.0.441_api-2.0.418 allows attackers to read arbitrary files.

CVE-2022-40843
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
40.4%
2022 1 PoC

The Tenda AC1200 V-W15Ev2 V15.11.0.10(1576) router is vulnerable to improper authorization / improper session management that allows the router login page to be bypassed. This leads to authenticated attackers having the ability to read the routers syslog.log file which contains the MD5 password of the Administrator's user account.

CVE-2022-35416
Software Genérico Web Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
6.6%
2022 1 PoC

H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

CVE-2022-31846
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
26.4%
2022 0 PoCs

A vulnerability in live_mfg.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.

CVE-2022-1386
Fusion Builder Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
93.6%
2022 CWE-918 9 PoCs

The Fusion Builder WordPress plugin before 3.6.2, used in the Avada theme, does not validate a parameter in its forms which could be used to initiate arbitrary HTTP requests. The data returned is then reflected back in the application's response. This could be used to interact with hosts on the server's local network bypassing firewalls and access control measures.

CVE-2022-2599
Anti-Malware Security and Brute-Force Firewall Web Networking Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
30.9%
2022 CWE-79 1 PoC

The Anti-Malware Security and Brute-Force Firewall WordPress plugin before 4.21.83 does not sanitise and escape some parameters before outputting them back in an admin dashboard, leading to Reflected Cross-Site Scripting

CVE-2022-31847
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
50.6%
2022 0 PoCs

A vulnerability in /cgi-bin/ExportAllSettings.sh of WAVLINK WN579 X3 M79X3.V5030.180719 allows attackers to obtain sensitive router information via a crafted POST request.

CVE-2022-29383
Software Genérico Networking Database Cloud ⚡ nuclei
N/A
UNKNOWN
EPSS
75.2%
2022 3 PoCs

NETGEAR ProSafe SSL VPN firmware FVS336Gv2 and FVS336Gv3 was discovered to contain a SQL injection vulnerability via USERDBDomains.Domainname at cgi-bin/platform.cgi.

CVE-2022-31845
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
53.1%
2022 0 PoCs

A vulnerability in live_check.shtml of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to obtain sensitive router information via execution of the exec cmd function.