5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3150
WP Custom Cursors | WordPress Cursor Plugin Web Database Windows
7.2
HIGH
EPSS
1.1%
2022 1 PoC

The WP Custom Cursors WordPress plugin before 3.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privileged users such as admin

CVE-2022-3243
Import all XML, CSV & TXT into WordPress Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 CWE-89 1 PoC

The Import all XML, CSV & TXT WordPress plugin before 6.5.8 does not properly sanitise and escape imported data before using them back SQL statements, leading to SQL injection exploitable by high privilege users such as admin

CVE-2022-0819
dolibarr/dolibarr General
7.2
HIGH
EPSS
1.7%
2022 CWE-94 1 PoC

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

CVE-2022-42140
Software Genérico General
7.2
HIGH
EPSS
9.6%
2022 1 PoC

Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

CVE-2022-4356
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-27925
🔥 KEV Software Genérico General
7.2
HIGH
EPSS
94.3%
2022 16 PoCs

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.

CVE-2022-42290
NVIDIA DGX servers Web
7.2
HIGH
EPSS
1.0%
2022 CWE-78 1 PoC

NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

CVE-2022-4359
WP RSS By Publishers Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The WP RSS By Publishers WordPress plugin through 0.1 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-34022
Software Genérico Database
7.2
HIGH
EPSS
0.3%
2022 1 PoC

SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive.

CVE-2022-40993
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'firmwall keyword WORD description (WORD|null)' command template.

CVE-2022-4722
ikus060/rdiffweb General
7.2
HIGH
EPSS
0.2%
2022 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.

CVE-2022-43970
WRT54GL Wireless-G Broadband Router Web Networking
7.2
HIGH
EPSS
4.0%
2022 CWE-120 3 PoCs

A buffer overflow vulnerability exists in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. A stack-based buffer overflow in the Start_EPI function within the httpd binary allows an authenticated attacker with administrator privileges to execute arbitrary commands on the underlying Linux operating system as root. This vulnerablity can be triggered over the network via a malicious POST request to /apply.cgi.

CVE-2022-40220
QUARTZ-GOLD Web
7.2
HIGH
EPSS
2.4%
2022 CWE-78 2 PoCs

An OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-41020
QUARTZ-GOLD Networking
7.2
HIGH
EPSS
2.0%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no vpn l2tp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> auth (on|off) password (WORD|null)' command template.

CVE-2022-41026
QUARTZ-GOLD Networking
7.2
HIGH
EPSS
3.5%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'no vpn pptp advanced name WORD dns (yes|no) mtu <128-16384> mru <128-16384> mppe (on|off) stateful (on|off) options WORD' command template.

CVE-2022-4324
Custom Field Template Web Windows
7.2
HIGH
EPSS
1.2%
2022 1 PoC

The Custom Field Template WordPress plugin before 2.5.8 unserialises the content of an imported file, which could lead to PHP object injections issues when a high privilege user import (intentionally or not) a malicious Customizer Styling file and a suitable gadget chain is present on the blog.

CVE-2022-21600
MySQL Server Database
7.2
HIGH
EPSS
1.3%
2022 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-0968
microweber/microweber Web ⚡ nuclei
7.2
HIGH
EPSS
1.4%
2022 CWE-190 1 PoC

The microweber application allows large characters to insert in the input field "fist & last name" which can allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request. in microweber/microweber in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-40997
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.4%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the 'gre index <1-8> destination A.B.C.D/M description (WORD|null)' command template.

CVE-2022-4268
Plugin Logic Web Database Windows
7.2
HIGH
EPSS
0.7%
2022 2 PoCs

The Plugin Logic WordPress plugin before 1.0.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin