33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4873
NF20 Networking
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

CVE-2022-47115
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepauth parameter at /goform/WifiBasicSet.

CVE-2022-45025
Software Genérico General
9.8
CRITICAL
EPSS
42.6%
2022 1 PoC

Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.

CVE-2022-3463
Contact Form Plugin – Fastest Contact Form Builder Plugin for WordPress by Fluent Forms Web Windows
9.8
CRITICAL
EPSS
1.4%
2022 CWE-1236 1 PoC

The Contact Form Plugin WordPress plugin before 4.3.13 does not validate and escape fields when exporting form entries as CSV, leading to a CSV injection

CVE-2022-4774
Bit Form Web Windows
9.8
CRITICAL
EPSS
8.0%
2022 1 PoC

The Bit Form WordPress plugin before 1.9 does not validate the file types uploaded via it's file upload form field, allowing unauthenticated users to upload arbitrary files types such as PHP or HTML files to the server, leading to Remote Code Execution.

CVE-2022-40347
Software Genérico Web Database
9.8
CRITICAL
EPSS
5.8%
2022 2 PoCs

SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.

CVE-2022-48079
Software Genérico Web
9.8
CRITICAL
EPSS
1.5%
2022 2 PoCs

Monnai aaPanel host system v1.5 contains an access control issue which allows attackers to escalate privileges and execute arbitrary code via uploading a crafted PHP file to the virtual host directory of the system.

CVE-2022-46589
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.netstat_option parameter in the tools_netstat (sub_41E730) function.

CVE-2022-47862
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.

CVE-2022-45715
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pLanPortRange and pWanPortRange parameters in the formSetPortMapping function.

CVE-2022-45706
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the hostname parameter in the formSetNetCheckTools function.

CVE-2022-33175
Software Genérico Web
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 have an insecure permissions setting on the user.token field that is accessible to everyone through the /cgi/get_param.cgi HTTP API. This leads to disclosing active session ids of currently logged-in administrators. The session id can then be reused to act as the administrator, allowing reading of the cleartext password, or reconfiguring the device.

CVE-2022-43110
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a remote attacker to configure the system via an unspecified web interface. An unauthenticated remote attacker can make changes to the system including: changing the web interface admin password, view/change system configuration, enumerate connected UPS devices and shut down connected UPS devices. This extends to being able to configure operating system commands that should run if the system detects a connected UPS shutting down.

CVE-2022-29842
My Cloud OS 5 Cloud
9.8
CRITICAL
EPSS
0.7%
2022 CWE-77 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability that could allow an attacker to execute code in the context of the root user on a vulnerable CGI file was discovered in Western Digital My Cloud OS 5 devicesThis issue affects My Cloud OS 5: before 5.26.119.

CVE-2022-31704
vRealize Log Insight (vRLI) General ⚡ nuclei
9.8
CRITICAL
EPSS
89.8%
2022 1 PoC

The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.

CVE-2022-42064
Software Genérico Database
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Online Diagnostic Lab Management System version 1.0 remote exploit that bypasses login with SQL injection and then uploads a shell.

CVE-2022-4050
JoomSport Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.2%
2022 1 PoC

The JoomSport WordPress plugin before 5.2.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-1768
RSVPMaker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.1%
2022 CWE-89 1 PoC

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

CVE-2022-44249
Software Genérico General
9.8
CRITICAL
EPSS
16.6%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.