33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38923
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru v3.9 processes an insufficiently sanitized HTTP Header allowing MySQL Injection in the 'User-Agent' field using a Time-based blind SLEEP payload.

CVE-2022-44255
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a pre-authentication buffer overflow in the main function via long post data.

CVE-2022-46584
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_deny (sub_415D7C) function.

CVE-2022-41573
Software Genérico Web
9.8
CRITICAL
EPSS
10.0%
2022 1 PoC

An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading of executable files. A user can upload a .png file containing PHP code and then rename it to have the .php extension. It will then be accessible at an images/common/ URI for remote code execution.

CVE-2022-36179
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Fusiondirectory 1.3 suffers from Improper Session Handling.

CVE-2022-0540
Jira Core Server Web ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2022 1 PoC

A vulnerability in Jira Seraph allows a remote, unauthenticated attacker to bypass authentication by sending a specially crafted HTTP request. This affects Atlassian Jira Server and Data Center versions before 8.13.18, versions 8.14.0 and later before 8.20.6, and versions 8.21.0 and later before 8.22.0. This also affects Atlassian Jira Service Management Server and Data Center versions before 4.13.18, versions 4.14.0 and later before 4.20.6, and versions 4.21.0 and later before 4.22.0.

CVE-2022-46596
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the del_num parameter in the icp_delete_img (sub_41DEDC) function.

CVE-2022-24082
Pega Infinity Cloud
9.8
CRITICAL
EPSS
45.6%
2022 CWE-502 1 PoC

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

CVE-2022-45173
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.

CVE-2022-45477
Telepad General
9.8
CRITICAL
EPSS
9.5%
2022 CWE-306 1 PoC

Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-31736
Thunderbird General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVE-2022-40089
Software Genérico Web
9.8
CRITICAL
EPSS
2.9%
2022 3 PoCs

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

CVE-2022-29464
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 50 PoCs

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and

CVE-2022-33321
PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE PV-DR006L-SET-M Web
9.8
CRITICAL
EPSS
0.8%
2022 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unaut

CVE-2022-40055
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

CVE-2022-0547
OpenVPN Networking
9.8
CRITICAL
EPSS
0.5%
2022 CWE-305 1 PoC

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVE-2022-44191
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

CVE-2022-4059
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
56.6%
2022 1 PoC

The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-44151
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

CVE-2022-43213
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.