5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2821
namelessmc/nameless General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-304 1 PoC

Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.

CVE-2022-34715
Windows Server 2022 Windows
9.8
CRITICAL
EPSS
38.9%
2022 1 PoC

Windows Network File System Remote Code Execution Vulnerability

CVE-2022-46072
Software Genérico DevOps Database
9.8
CRITICAL
EPSS
1.5%
2022 2 PoCs

Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection.

CVE-2022-42842
macOS General
9.8
CRITICAL
EPSS
4.1%
2022 6 PoCs

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. A remote user may be able to cause kernel code execution.

CVE-2022-43775
Delta Electronics DIAEnergie Database
9.8
CRITICAL
EPSS
1.9%
2022 1 PoC

The HICT_Loop class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

CVE-2022-44251
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.

CVE-2022-46580
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the user_edit_page parameter in the wifi_captive_portal function.

CVE-2022-3268
ikus060/minarca General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-521 1 PoC

Weak Password Requirements in GitHub repository ikus060/minarca prior to 4.2.2.

CVE-2022-47864
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.

CVE-2022-44187
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow via wan_dns1_pri.

CVE-2022-31937
Software Genérico Web Networking
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Netgear N300 wireless router wnr2000v4-V1.0.0.70 was discovered to contain a stack overflow via strcpy in uhttpd.

CVE-2022-32504
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart Lock 3.0 before 3.3.5 and 2.0 before 2.12.4, as well as Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2.

CVE-2022-46598
Software Genérico General
9.8
CRITICAL
EPSS
16.6%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a command injection vulnerability via the wps_sta_enrollee_pin parameter in the action set_sta_enrollee_pin_5g function.

CVE-2022-44136
Software Genérico Web
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

CVE-2022-47986
🔥 KEV Aspera Faspex Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 CWE-502 4 PoCs

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.

CVE-2022-0748
post-loader Web
9.8
CRITICAL
EPSS
1.2%
2022 1 PoC

The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.

CVE-2022-44291
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
66.4%
2022 0 PoCs

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

CVE-2022-40916
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2022 2 PoCs

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

CVE-2022-48253
Software Genérico Web
9.8
CRITICAL
EPSS
33.5%
2022 1 PoC

nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

CVE-2022-20473
Android General
9.8
CRITICAL
EPSS
50.9%
2022 1 PoC

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239267173