33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4606
flatpressblog/flatpress Web
8.8
HIGH
EPSS
12.0%
2022 CWE-98 1 PoC

PHP Remote File Inclusion in GitHub repository flatpressblog/flatpress prior to 1.3.

CVE-2022-37205
Software Genérico Web Database
8.8
HIGH
EPSS
1.1%
2022 2 PoCs

JFinal CMS 5.1.0 is affected by: SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-48580
SL 1 General
8.8
HIGH
EPSS
0.5%
2022 CWE-78 1 PoC

A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVE-2022-42199
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2022 2 PoCs

Simple Exam Reviewer Management System v1.0 is vulnerable to Cross Site Request Forgery (CSRF) via the Exam List.

CVE-2022-1802
Firefox ESR Web
8.8
HIGH
EPSS
67.9%
2022 1 PoC

If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.

CVE-2022-30605
AVideo Web
8.8
HIGH
EPSS
0.7%
2022 CWE-384 1 PoC

A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-3860
Visual Email Designer for WooCommerce Web Database Windows
8.8
HIGH
EPSS
0.7%
2022 1 PoC

The Visual Email Designer for WooCommerce WordPress plugin before 1.7.2 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as author.

CVE-2022-21154
Leadtools General
8.8
HIGH
EPSS
0.2%
2022 CWE-190 1 PoC

An integer overflow vulnerability exists in the fltSaveCMP functionality of Leadtools 22. A specially-crafted BMP file can lead to an integer overflow, that in turn causes a buffer overflow. An attacker can provide a malicious BMP file to trigger this vulnerability.

CVE-2022-41264
BASIS General
8.8
HIGH
EPSS
0.8%
2022 CWE-94 1 PoC

Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful exploitation the attacker can have full control of the system to which the class belongs, causing a high impact on the integrity of the application.

CVE-2022-48584
SL 1 General
8.8
HIGH
EPSS
0.5%
2022 CWE-78 1 PoC

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVE-2022-31741
Thunderbird Web
8.8
HIGH
EPSS
0.3%
2022 1 PoC

A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVE-2022-34753
SpaceLogic C-Bus Home Controller General ⚡ nuclei
8.8
HIGH
EPSS
93.8%
2022 CWE-78 2 PoCs

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)

CVE-2022-0721
microweber/microweber General
8.8
HIGH
EPSS
0.4%
2022 CWE-215 1 PoC

Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-48603
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-1997
francoisjacquet/rosariosis Web
8.8
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.

CVE-2022-26009
LinkHub Mesh Wifi Cloud
8.8
HIGH
EPSS
0.5%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the confsrv ucloud_set_node_location functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-28768
Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) General
8.8
HIGH
EPSS
0.0%
2022 CWE-689 1 PoC

The Zoom Client for Meetings Installer for macOS (Standard and for IT Admin) before version 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to root.

CVE-2022-46394
Software Genérico General
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r39p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

CVE-2022-45928
Software Genérico General
8.8
HIGH
EPSS
2.8%
2022 3 PoCs

A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.

CVE-2022-45600
Software Genérico Networking
8.8
HIGH
EPSS
41.8%
2022 1 PoC

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.