33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-36787
webvendome Database
9.8
CRITICAL
EPSS
0.2%
2022 CWE-89 1 PoC

webvendome - webvendome SQL Injection. SQL Injection in the Parameter " DocNumber" Request : Get Request : /webvendome/showfiles.aspx?jobnumber=nullDoc Number=HERE.

CVE-2022-27773
Ivanti Endpoint Manger General
9.8
CRITICAL
EPSS
6.9%
2022 1 PoC

A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated privileges.

CVE-2022-31181
PrestaShop Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
78.3%
2022 CWE-89 0 PoCs

PrestaShop is an Open Source e-commerce platform. In versions from 1.6.0.10 and before 1.7.8.7 PrestaShop is subject to an SQL injection vulnerability which can be chained to call PHP's Eval function on attacker input. The problem is fixed in version 1.7.8.7. Users are advised to upgrade. Users unable to upgrade may delete the MySQL Smarty cache feature.

CVE-2022-3254
WordPress Classifieds Plugin – Ad Directory & Listings by AWP Classifieds Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.6%
2022 CWE-89 1 PoC

The WordPress Classifieds Plugin WordPress plugin before 4.3 does not properly sanitise and escape some parameters before using them in a SQL statement via an AJAX action available to unauthenticated users and when a specific premium module is active, leading to a SQL injection

CVE-2022-4063
InPost Gallery Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
88.0%
2022 1 PoC

The InPost Gallery WordPress plugin before 2.1.4.1 insecurely uses PHP's extract() function when rendering HTML views, allowing attackers to force the inclusion of malicious files & URLs, which may enable them to run code on servers.

CVE-2022-45721
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the picName parameter in the formDelWewifiPic function.

CVE-2022-1453
RSVPMaker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
61.0%
2022 CWE-89 0 PoCs

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-util.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.5.

CVE-2022-44200
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.0.8, V1.3.1.64 is vulnerable to Buffer Overflow via parameters: stamode_dns1_pri and stamode_dns1_sec.

CVE-2022-40624
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2022 1 PoC

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

CVE-2022-45719
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the gotoUrl parameter in the formPortalAuth function.

CVE-2022-41838
OpenImageIO General
9.8
CRITICAL
EPSS
1.1%
2022 CWE-122 1 PoC

A code execution vulnerability exists in the DDS scanline parsing functionality of OpenImageIO Project OpenImageIO v2.4.4.2. A specially-crafted .dds can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-23221
Software Genérico General
9.8
CRITICAL
EPSS
26.6%
2022 4 PoCs

H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.

CVE-2022-42491
QUARTZ-GOLD General
9.8
CRITICAL
EPSS
3.8%
2022 CWE-78 1 PoC

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's M2M_CONFIG_SET command

CVE-2022-44196
Software Genérico Networking
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via parameter openvpn_push1.

CVE-2022-2818
cockpit-hq/cockpit General
9.8
CRITICAL
EPSS
1.5%
2022 CWE-212 1 PoC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

CVE-2022-45707
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijack function.

CVE-2022-46290
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-122 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the ORCA format nAtoms functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.The loop that stores the coordinates does not check its index against nAtoms

CVE-2022-2024
gogs/gogs General
9.8
CRITICAL
EPSS
42.3%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

CVE-2022-40877
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.

CVE-2022-45716
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the indexSet parameter in the formIPMacBindDel function.