5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2073
getgrav/grav General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-94 1 PoC

Code Injection in GitHub repository getgrav/grav prior to 1.7.34.

CVE-2022-38168
Software Genérico General
9.1
CRITICAL
EPSS
0.5%
2022 1 PoC

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

CVE-2022-23066
rbpf General
9.1
CRITICAL
EPSS
0.9%
2022 CWE-682 2 PoCs

In Solana rBPF versions 0.2.26 and 0.2.27 are affected by Incorrect Calculation which is caused by improper implementation of sdiv instruction. This can lead to the wrong execution path, resulting in huge loss in specific cases. For example, the result of a sdiv instruction may decide whether to transfer tokens or not. The vulnerability affects both integrity and may cause serious availability problems.

CVE-2022-3782
Keycloak General
9.1
CRITICAL
EPSS
0.1%
2022 1 PoC

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

CVE-2022-27498
lansweeper Web
9.1
CRITICAL
EPSS
44.7%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-32763
lansweeper Web
9.1
CRITICAL
EPSS
0.9%
2022 CWE-184 1 PoC

A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-29830
GX Works3 Cloud
9.1
CRITICAL
EPSS
1.2%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthenticated attackers may obtain information about project files illegally.

CVE-2022-25784
SiteManager Web
9.1
CRITICAL
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVE-2022-26007
InRouter302 Networking
9.1
CRITICAL
EPSS
3.5%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-33150
R1510 General
9.1
CRITICAL
EPSS
1.2%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-28223
Software Genérico General
9.1
CRITICAL
EPSS
0.8%
2022 1 PoC

Tekon KIO devices through 2022-03-30 allow an authenticated admin user to escalate privileges to root by uploading a malicious Lua plugin.

CVE-2022-37337
Orbi Router RBR750 Web Networking
9.1
CRITICAL
EPSS
0.7%
2022 CWE-78 3 PoCs

A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-33326
R1510 Web
9.1
CRITICAL
EPSS
3.5%
2022 CWE-78 1 PoC

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/config_rollback/` API is affected by a command injection vulnerability.

CVE-2022-40842
Software Genérico Web
9.1
CRITICAL
EPSS
0.7%
2022 1 PoC

ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.

CVE-2022-42484
FreshTomato Web
9.1
CRITICAL
EPSS
0.6%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-26851
PowerScale OneFS General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-330 1 PoC

Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

CVE-2022-21723
pjproject General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-125 1 PoC

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.

CVE-2022-21217
Software Genérico Web
9.1
CRITICAL
EPSS
0.4%
2022 CWE-457 1 PoC

An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1811
publify/publify General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.