33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46289
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-122 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.nAtoms calculation wrap-around, leading to a small buffer allocation

CVE-2022-38580
Software Genérico General
9.8
CRITICAL
EPSS
48.8%
2022 1 PoC

Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).

CVE-2022-50981
VibroLine VLX1 HD 5.0 General
9.8
CRITICAL
EPSS
0.0%
2022 CWE-306 2 PoCs

An unauthenticated remote attacker can gain full access on the affected devices as they are shipped without a password by default and setting one is not enforced.

CVE-2022-43333
Software Genérico Web
9.8
CRITICAL
EPSS
2.9%
2022 1 PoC

Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.

CVE-2022-2143
iView General
9.8
CRITICAL
EPSS
58.3%
2022 CWE-77 1 PoC

The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.

CVE-2022-42948
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
21.8%
2022 2 PoCs

Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing components. By injecting crafted HTML code, it is possible to remotely execute code in the Cobalt Strike UI.

CVE-2022-24112
🔥 KEV Apache APISIX Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 CWE-290 16 PoCs

An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.

CVE-2022-2821
namelessmc/nameless General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-304 1 PoC

Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

CVE-2022-34715
Windows Server 2022 Windows
9.8
CRITICAL
EPSS
38.9%
2022 1 PoC

Windows Network File System Remote Code Execution Vulnerability

CVE-2022-46072
Software Genérico DevOps Database
9.8
CRITICAL
EPSS
1.5%
2022 2 PoCs

Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.

CVE-2022-42842
macOS General
9.8
CRITICAL
EPSS
4.1%
2022 6 PoCs

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVE-2022-43775
Delta Electronics DIAEnergie Database
9.8
CRITICAL
EPSS
1.9%
2022 1 PoC

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

CVE-2022-44251
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

CVE-2022-46580
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.

CVE-2022-3268
ikus060/minarca General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

CVE-2022-47864
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.

CVE-2022-44187
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

CVE-2022-31937
Software Genérico Web Networking
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

CVE-2022-32504
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-46598
Software Genérico General
9.8
CRITICAL
EPSS
16.6%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.