3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-26780
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.9%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-21391
Communications Billing and Revenue Management Web Database
9.9
CRITICAL
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communicat

CVE-2022-32572
AVideo Web
9.9
CRITICAL
EPSS
22.9%
2022 CWE-78 1 PoC

An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-45808
LearnPress – WordPress LMS Plugin Web Database Windows ⚡ nuclei
9.9
CRITICAL
EPSS
83.6%
2022 CWE-89 1 PoC

SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

CVE-2022-21809
InRouter302 Web Networking
9.9
CRITICAL
EPSS
1.4%
2022 CWE-377 1 PoC

A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.

CVE-2022-29517
lansweeper Web
9.9
CRITICAL
EPSS
46.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-26782
InRouter302 Web Networking
9.9
CRITICAL
EPSS
1.3%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_set_item` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-26510
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.5%
2022 CWE-347 1 PoC

A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-26781
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.9%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_print` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-21276
Communications Billing and Revenue Management Web Database
9.9
CRITICAL
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communicat

CVE-2022-24663
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
2.1%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.

CVE-2022-2884
GitLab DevOps Web
9.9
CRITICAL
EPSS
69.0%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVE-2022-30534
AVideo Web
9.9
CRITICAL
EPSS
12.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-24665
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
2.1%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

CVE-2022-2992
GitLab DevOps Web
9.9
CRITICAL
EPSS
93.7%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVE-2022-32573
lansweeper Web
9.9
CRITICAL
EPSS
25.4%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the AssetActions.aspx addDoc functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-24664
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
1.5%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.

CVE-2022-41272
NetWeaver Process Integration Web
9.9
CRITICAL
EPSS
0.7%
2022 CWE-862 2 PoCs

An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and int

CVE-2022-36786
DSL-224 Web Networking
9.9
CRITICAL
EPSS
0.4%
2022 1 PoC

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

CVE-2022-26085
InRouter302 Web Networking
9.9
CRITICAL
EPSS
2.7%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.