5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-43216
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2022 1 PoC

AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

CVE-2022-32763
lansweeper Web
9.1
CRITICAL
EPSS
0.9%
2022 CWE-184 1 PoC

A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-27498
lansweeper Web
9.1
CRITICAL
EPSS
44.7%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-21217
Software Genérico Web
9.1
CRITICAL
EPSS
0.4%
2022 CWE-457 1 PoC

An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-3782
Keycloak General
9.1
CRITICAL
EPSS
0.1%
2022 1 PoC

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

CVE-2022-1399
CMDB General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-88 1 PoC

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-46836
Checkmk Web
9.1
CRITICAL
EPSS
2.1%
2022 CWE-20 1 PoC

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

CVE-2022-26851
PowerScale OneFS General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-330 1 PoC

Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

CVE-2022-22149
lansweeper Web Database
9.1
CRITICAL
EPSS
7.0%
2022 CWE-89 2 PoCs

A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-0742
Kernel General
9.1
CRITICAL
EPSS
2.2%
2022 CWE-275 1 PoC

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.

CVE-2022-33326
R1510 Web
9.1
CRITICAL
EPSS
3.5%
2022 CWE-78 1 PoC

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/config_rollback/` API is affected by a command injection vulnerability.

CVE-2022-29511
lansweeper Web
9.1
CRITICAL
EPSS
16.6%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-24856
flyteconsole General ⚡ nuclei
9.1
CRITICAL
EPSS
81.9%
2022 CWE-918 0 PoCs

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a wor

CVE-2022-2062
nocodb/nocodb General
9.1
CRITICAL
EPSS
1.3%
2022 CWE-209 1 PoC

Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-41923
grails-spring-security-core Web
9.1
CRITICAL
EPSS
0.3%
2022 CWE-269 1 PoC

Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework applications, access to the targeted endpoint will be granted based on meeting the authorization requirements of the donor endpoint, which can result in a privilege escalation attack. This vulnerability has been patched in grails-spring-security-core versions 3.3.2, 4.0.5 and 5.1.1. Impacted Applications: Grails Spring Sec

CVE-2022-4802
usememos/memos General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1931
polonel/trudesk General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-821 1 PoC

Incorrect Synchronization in GitHub repository polonel/trudesk prior to 1.2.3.

CVE-2022-36323
RUGGEDCOM RM1224 LTE(4G) EU General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-74 1 PoC

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

CVE-2022-2217
ionicabizau/parse-url Web
9.1
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Generic in GitHub repository ionicabizau/parse-url prior to 7.0.0.

CVE-2022-26002
InRouter302 Networking
9.1
CRITICAL
EPSS
7.7%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to remote code execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.