5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-44832
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2022 1 PoC

D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

CVE-2022-21186
@acrontum/filesystem-template Web
9.8
CRITICAL
EPSS
6.6%
2022 1 PoC

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.

CVE-2022-41352
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2022 8 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

CVE-2022-4395
Membership For WooCommerce Web Windows
9.8
CRITICAL
EPSS
76.3%
2022 3 PoCs

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

CVE-2022-40021
Software Genérico General
9.8
CRITICAL
EPSS
3.3%
2022 1 PoC

QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.

CVE-2022-45481
Lazy Mouse General
9.8
CRITICAL
EPSS
2.6%
2022 CWE-306 1 PoC

The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-44202
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

CVE-2022-2068
OpenSSL General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbi

CVE-2022-44250
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

CVE-2022-35866
Backup and Recovery Database
9.8
CRITICAL
EPSS
0.4%
2022 CWE-798 1 PoC

This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17139.

CVE-2022-36784
Elsight Halo Web
9.8
CRITICAL
EPSS
1.9%
2022 1 PoC

Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.

CVE-2022-24706
🔥 KEV Apache CouchDB Web Networking
9.8
CRITICAL
EPSS
94.4%
2022 CWE-1188 9 PoCs

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVE-2022-26143
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.1%
2022 2 PoCs

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVE-2022-44000
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an exposed internal communications interface, it is possible to execute arbitrary system commands on the server.

CVE-2022-21420
Coherence Database
9.8
CRITICAL
EPSS
1.6%
2022 1 PoC

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-37055
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
80.5%
2022 1 PoC

D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,

CVE-2022-47758
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 2 PoCs

Nanoleaf firmware v7.1.1 and below is missing TLS verification, allowing attackers to execute arbitrary code via a DNS hijacking attack.

CVE-2022-34270
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

CVE-2022-0651
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
69.4%
2022 CWE-89 0 PoCs

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CVE-2022-1440
yarkeev/git-interface General
9.8
CRITICAL
EPSS
8.5%
2022 CWE-78 1 PoC

Command Injection vulnerability in git-interface@2.1.1 in GitHub repository yarkeev/git-interface prior to 2.1.2. If both are provided by user input, then the use of a `--upload-pack` command-line argument feature of git is also supported for `git clone`, which would then allow for any operating system command to be spawned by the attacker.