3391 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2022-4446
tsolucio/corebos Web
9.8
CRITICAL
EPSS
0.7%
2022 CWE-98 1 PoC

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2022-44118
Software Genérico Web
9.8
CRITICAL
EPSS
10.3%
2022 1 PoC

dedecmdv6 v6.1.9 is vulnerable to Remote Code Execution (RCE) via file_manage_control.php.

CVE-2022-40296
PHP Point of Sale Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-918 1 PoC

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

CVE-2022-21587
🔥 KEV Web Applications Desktop Integrator Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 6 PoCs

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-38922
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.

CVE-2022-34128
Software Genérico Web
9.8
CRITICAL
EPSS
32.7%
2022 1 PoC

The Cartography (aka positions) plugin before 6.0.1 for GLPI allows remote code execution via PHP code in the POST data to front/upload.php.

CVE-2022-38923
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.

CVE-2022-4059
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
56.6%
2022 1 PoC

The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-45132
Software Genérico Web
9.8
CRITICAL
EPSS
4.7%
2022 1 PoC

In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input as a Jinja2 template in a way that can be used to trigger remote code execution in the LAVA server.

CVE-2022-3241
Build App Online Web Database Windows
9.8
CRITICAL
EPSS
4.4%
2022 1 PoC

The Build App Online WordPress plugin before 1.0.19 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

CVE-2022-3603
Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list Web Windows
9.8
CRITICAL
EPSS
2.0%
2022 1 PoC

The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.

CVE-2022-4866
usememos/memos Web
9.8
CRITICAL
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-43138
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

CVE-2022-45599
Software Genérico Web Networking
9.8
CRITICAL
EPSS
1.3%
2022 1 PoC

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gain escalated privileges only when specific conditions regarding a given accounts hashed password.

CVE-2022-0540
Jira Core Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2022 1 PoC

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.

CVE-2022-47860
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.

CVE-2022-39180
College Management System v1.0 Web Database
9.8
CRITICAL
EPSS
0.2%
2022 CWE-89 1 PoC

College Management System v1.0 - SQL Injection (SQLi). By inserting SQL commands to the username and password fields in the login.php page

CVE-2022-3574
WPForms Pro Web Windows
9.8
CRITICAL
EPSS
1.3%
2022 CWE-1236 1 PoC

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

CVE-2022-43333
Software Genérico Web
9.8
CRITICAL
EPSS
2.9%
2022 1 PoC

Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

CVE-2022-25148
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
57.8%
2022 CWE-89 1 PoC

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.