5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-33327
R1510 Web
9.1
CRITICAL
EPSS
3.5%
2022 CWE-78 1 PoC

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/remove_sniffer_raw_log/` API is affected by a command injection vulnerability.

CVE-2022-1947
polonel/trudesk General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-480 1 PoC

Use of Incorrect Operator in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-42905
Software Genérico General
9.1
CRITICAL
EPSS
6.1%
2022 3 PoCs

In wolfSSL before 5.5.2, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS 1.3 client or network attacker can trigger a buffer over-read on the heap of 5 bytes. (WOLFSSL_CALLBACKS is only intended for debugging.)

CVE-2022-39227
python-jwt General
9.1
CRITICAL
EPSS
71.3%
2022 CWE-290 3 PoCs

python-jwt is a module for generating and verifying JSON Web Tokens. Versions prior to 3.3.4 are subject to Authentication Bypass by Spoofing, resulting in identity spoofing, session hijacking or authentication bypass. An attacker who obtains a JWT can arbitrarily forge its contents without knowing the secret key. Depending on the application, this may for example enable the attacker to spoof other user's identities, hijack their sessions, or bypass authentication. Users should upgrade to version 3.3.4. There are no known workarounds.

CVE-2022-0482
alextselegidis/easyappointments General ⚡ nuclei
9.1
CRITICAL
EPSS
90.8%
2022 CWE-359 4 PoCs

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

CVE-2022-46836
Checkmk Web
9.1
CRITICAL
EPSS
2.1%
2022 CWE-20 1 PoC

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

CVE-2022-21145
lansweeper Web
9.1
CRITICAL
EPSS
4.1%
2022 CWE-80 2 PoCs

A stored cross-site scripting vulnerability exists in the WebUserActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-45796
SHARP multifunction printers General
9.1
CRITICAL
EPSS
2.5%
2022 CWE-77 1 PoC

Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or earlier, and Digital Multifunctional System (Monochrome) 200 or earlier, 211 or earlier, 102 or earlier, 453 or earlier, 400 or earlier, 202 or earlier, 602 or earlier, 500 or earlier, 401 or earlier allows remote attackers to execute arbitrary commands via unspecified vectors.

CVE-2022-36323
RUGGEDCOM RM1224 LTE(4G) EU General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-74 1 PoC

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

CVE-2022-32763
lansweeper Web
9.1
CRITICAL
EPSS
0.9%
2022 CWE-184 1 PoC

A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-0724
microweber/microweber General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-922 1 PoC

Insecure Storage of Sensitive Information in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-34850
R1510 General
9.1
CRITICAL
EPSS
1.4%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel R1510 3.1.16 and 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-4802
usememos/memos General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-26851
PowerScale OneFS General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-330 1 PoC

Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

CVE-2022-45891
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).

CVE-2022-43216
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2022 1 PoC

AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

CVE-2022-41561
TIBCO JasperReports Server Cloud
9.1
CRITICAL
EPSS
4.2%
2022 1 PoC

The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows a privileged/administrative attacker with network access to execute Remote Code Execution to obtain a reverse shell on the affected system.

CVE-2022-1034
star7th/showdoc General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-434 1 PoC

There is a Unrestricted Upload of File vulnerability in ShowDoc v2.10.3 in GitHub repository star7th/showdoc prior to 2.10.4.

CVE-2022-44900
Software Genérico General
9.1
CRITICAL
EPSS
28.6%
2022 2 PoCs

A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and earlier allows attackers to write arbitrary files via extracting a crafted 7z file.

CVE-2022-2339
nocodb/nocodb General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-918 1 PoC

With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.