3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-23227
🔥 KEV Software Genérico Web
9.8
CRITICAL
EPSS
53.5%
2022 1 PoC

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

CVE-2022-3574
WPForms Pro Web Windows
9.8
CRITICAL
EPSS
1.3%
2022 CWE-1236 1 PoC

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

CVE-2022-45708
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function.

CVE-2022-2932
bustle/mobiledoc-kit Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.

CVE-2022-35156
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 2 PoCs

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

CVE-2022-32221
https://github.com/curl/curl Web
9.8
CRITICAL
EPSS
1.6%
2022 CWE-200 1 PoC

When doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously was used to issue a `PUT` request which used that callback. This flaw may surprise the application and cause it to misbehave and either send off the wrong data or use memory after free or similar in the subsequent `POST` request. The problem exists in the logic for a reused handle when it is changed from a PUT to a POST.

CVE-2022-46966
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.

CVE-2022-25148
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
57.8%
2022 CWE-89 1 PoC

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CVE-2022-40471
Software Genérico Web
9.8
CRITICAL
EPSS
90.3%
2022 3 PoCs

Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

CVE-2022-4305
Login as User or Customer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
83.1%
2022 1 PoC

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

CVE-2022-3921
Listingo Web Windows
9.8
CRITICAL
EPSS
7.8%
2022 1 PoC

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE

CVE-2022-46640
Software Genérico Web
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

CVE-2022-44188
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

CVE-2022-45173
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.

CVE-2022-3634
Contact Form 7 Database Addon Web Windows
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

CVE-2022-29464
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 50 PoCs

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and

CVE-2022-38923
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.

CVE-2022-3241
Build App Online Web Database Windows
9.8
CRITICAL
EPSS
4.4%
2022 1 PoC

The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection