33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4298
Wholesale Market Web Windows
9.8
CRITICAL
EPSS
55.7%
2022 1 PoC

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVE-2022-40471
Software Genérico Web
9.8
CRITICAL
EPSS
90.3%
2022 3 PoCs

Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

CVE-2022-44190
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

CVE-2022-45637
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVE-2022-43001
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

CVE-2022-44015
Software Genérico Database
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.

CVE-2022-46601
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.

CVE-2022-3900
Cooked Pro Web Windows
9.8
CRITICAL
EPSS
4.3%
2022 1 PoC

The Cooked Pro WordPress plugin before 1.7.5.7 does not properly validate or sanitize the recipe_args parameter before unserializing it in the cooked_loadmore action, allowing an unauthenticated attacker to trigger a PHP Object injection vulnerability.

CVE-2022-42837
macOS General
9.8
CRITICAL
EPSS
5.9%
2022 4 PoCs

An issue existed in the parsing of URLs. This issue was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, watchOS 9.2. A remote user may be able to cause unexpected app termination or arbitrary code execution.

CVE-2022-38488
Software Genérico Database
9.8
CRITICAL
EPSS
0.9%
2022 2 PoCs

logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter.

CVE-2022-34718
Windows 10 Version 1809 Windows
9.8
CRITICAL
EPSS
85.8%
2022 1 PoC

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2022-2166
mastodon/mastodon General
9.8
CRITICAL
EPSS
1.4%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.

CVE-2022-31692
Spring by VMware Web
9.8
CRITICAL
EPSS
7.4%
2022 3 PoCs

Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expects that Spring Security applies security to forward and include dispatcher types. The application uses the AuthorizationFilter either manually or via the authorizeHttpRequests() method. The application configures the FilterChainProxy to apply to forward and/or include requests (e.g. spring.security.filter.dispatcher-types = request, error

CVE-2022-4446
tsolucio/corebos Web
9.8
CRITICAL
EPSS
0.7%
2022 CWE-98 1 PoC

PHP Remote File Inclusion in GitHub repository tsolucio/corebos prior to 8.0.

CVE-2022-2932
bustle/mobiledoc-kit Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.

CVE-2022-33198
Accordions (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
31.2%
2022 CWE-264 0 PoCs

Unauthenticated WordPress Options Change vulnerability in Biplob Adhikari's Accordions plugin <= 2.0.2 at WordPress.

CVE-2022-44806
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow.

CVE-2022-42058
Software Genérico Networking
9.8
CRITICAL
EPSS
1.1%
2022 2 PoCs

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a stack overflow via the setRemoteWebManage function. This vulnerability allows attackers to cause a Denial of Service (DoS) via crafted overflow data.

CVE-2022-40087
Software Genérico Web
9.8
CRITICAL
EPSS
1.0%
2022 3 PoCs

Simple College Website v1.0 was discovered to contain an arbitrary file write vulnerability via the function file_put_contents(). This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-25299
cesanta/mongoose Web
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.