5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45893
Software Genérico General
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.

CVE-2022-48600
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-50895
Aero CMS Web Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

Aero CMS 0.0.1 contains a SQL injection vulnerability in the author parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, time-based, and UNION query techniques to extract sensitive database information and potentially compromise the system.

CVE-2022-39822
Software Genérico Web Database
8.8
HIGH
EPSS
0.1%
2022 1 PoC

In NOKIA NFM-T R19.9, a SQL Injection vulnerability occurs in /cgi-bin/R19.9/easy1350.pl of the VM Manager WebUI via the id or host HTTP GET parameter. An authenticated attacker is required for exploitation.

CVE-2022-43769
🔥 KEV Pentaho Business Analytics Server Web ⚡ nuclei
8.8
HIGH
EPSS
94.0%
2022 CWE-74 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.

CVE-2022-45768
Software Genérico Networking
8.8
HIGH
EPSS
4.5%
2022 1 PoC

Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.

CVE-2022-23067
ToolJet General
8.8
HIGH
EPSS
0.4%
2022 CWE-200 1 PoC

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.

CVE-2022-24401
TETRA Standard General
8.8
HIGH
EPSS
0.2%
2022 CWE-323 1 PoC

Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthenticated manner. An active adversary can manipulate the view of these counters in a mobile station, provoking keystream re-use. By sending crafted messages to the MS and analyzing MS responses, keystream for arbitrary frames can be recovered.

CVE-2022-34155
OAuth Single Sign On – SSO (OAuth Client) General
8.8
HIGH
EPSS
0.2%
2022 CWE-287 1 PoC

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.

CVE-2022-22026
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
0.5%
2022 1 PoC

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2022-34446
PowerPath Management Appliance General
8.8
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration.

CVE-2022-4287
Remote Desktop Manager Windows
8.8
HIGH
EPSS
0.4%
2022 1 PoC

Authentication bypass in local application lock feature in Devolutions Remote Desktop Manager  2022.3.26 and earlier on Windows allows malicious user to access the application.

CVE-2022-37719
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2022 1 PoC

A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.

CVE-2022-29778
Software Genérico Web
8.8
HIGH
EPSS
23.1%
2022 1 PoC

D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary code due to the hardcoded option Wake-On-Lan for the parameter 'descriptor' at SetVirtualServerSettings.php

CVE-2022-1316
zerotier/zerotierone General
8.8
HIGH
EPSS
0.1%
2022 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation

CVE-2022-1578
My wpdb Web Database Windows
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

CVE-2022-40469
Software Genérico General
8.8
HIGH
EPSS
4.9%
2022 1 PoC

iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.

CVE-2022-26485
🔥 KEV Firefox General
8.8
HIGH
EPSS
7.2%
2022 1 PoC

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.