3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-43333
Software Genérico Web
9.8
CRITICAL
EPSS
2.9%
2022 1 PoC

Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

CVE-2022-4047
Return Refund and Exchange For WooCommerce Web Windows
9.8
CRITICAL
EPSS
73.3%
2022 2 PoCs

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVE-2022-45173
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.

CVE-2022-46640
Software Genérico Web
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

CVE-2022-40296
PHP Point of Sale Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-918 1 PoC

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

CVE-2022-47860
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.

CVE-2022-35156
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.3%
2022 2 PoCs

Bus Pass Management System 1.0 was discovered to contain a SQL Injection vulnerability via the searchdata parameter at /buspassms/download-pass.php..

CVE-2022-4298
Wholesale Market Web Windows
9.8
CRITICAL
EPSS
55.7%
2022 1 PoC

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVE-2022-40087
Software Genérico Web
9.8
CRITICAL
EPSS
1.0%
2022 3 PoCs

Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-24437
git-pull-or-clone Web
9.8
CRITICAL
EPSS
10.4%
2022 1 PoC

The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.

CVE-2022-23227
🔥 KEV Software Genérico Web
9.8
CRITICAL
EPSS
53.5%
2022 1 PoC

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

CVE-2022-3921
Listingo Web Windows
9.8
CRITICAL
EPSS
7.8%
2022 1 PoC

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE

CVE-2022-4060
User Post Gallery Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.7%
2022 1 PoC

The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.

CVE-2022-45132
Software Genérico Web
9.8
CRITICAL
EPSS
4.7%
2022 1 PoC

In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.

CVE-2022-4099
Joy Of Text Lite Web Database Windows
9.8
CRITICAL
EPSS
4.3%
2022 1 PoC

The Joy Of Text Lite WordPress plugin before 2.3.1 does not properly sanitise and escape some parameters before using them in SQL statements accessible to unauthenticated users, leading to unauthenticated SQL injection

CVE-2022-4407
thorsten/phpmyfaq Web
9.8
CRITICAL
EPSS
6.1%
2022 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Reflected in GitHub repository thorsten/phpmyfaq prior to 3.1.9.

CVE-2022-39180
College Management System v1.0 Web Database
9.8
CRITICAL
EPSS
0.2%
2022 CWE-89 1 PoC

College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

CVE-2022-33198
Accordions (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
31.2%
2022 CWE-264 0 PoCs

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

CVE-2022-4939
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Web Windows
9.8
CRITICAL
EPSS
20.3%
2022 CWE-862 1 PoC

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the membership registration form in a way that allows them to set the role for registration to that of any user including administrators. Once configured, the attacker can then register as an administrator.