5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-48588
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-46914
Software Genérico General
8.8
HIGH
EPSS
0.7%
2022 2 PoCs

An issue in the firmware update process of TP-LINK TL-WA801N / TL-WA801ND V1 v3.12.16 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVE-2022-35135
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.

CVE-2022-30759
Software Genérico General
8.8
HIGH
EPSS
0.1%
2022 2 PoCs

In Nokia One-NDS (aka Network Directory Server) through 20.9, some Sudo permissions can be exploited by some users to escalate to root privileges and execute arbitrary commands.

CVE-2022-50975
VibroLine VLX1 HD 5.0 General
8.8
HIGH
EPSS
0.0%
2022 CWE-346 2 PoCs

An unauthenticated remote attacker is able to use an existing session id of a logged in user and gain full access to the device if configuration via ethernet is enabled.

CVE-2022-22111
DaybydayCRM General
8.8
HIGH
EPSS
0.3%
2022 CWE-862 1 PoC

In DayByDay CRM, version 2.2.0 is vulnerable to missing authorization. Any application user in the application who has update user permission enabled is able to change the password of other users, including the administrator’s. This allows the attacker to gain access to the highest privileged user in the application.

CVE-2022-34375
Dell Container Storage Modules DevOps
8.8
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Dell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated malicious user with low privileges could exploit this vulnerability leading to unintentional access to path outside of restricted directory.

CVE-2022-29468
AVideo Web
8.8
HIGH
EPSS
1.3%
2022 CWE-352 1 PoC

A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to increased privileges. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-48596
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-0520
radareorg/radare2 General
8.8
HIGH
EPSS
0.2%
2022 CWE-416 1 PoC

Use After Free in NPM radare2.js prior to 5.6.2.

CVE-2022-0690
microweber/microweber Web
8.8
HIGH
EPSS
0.9%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in Packagist microweber/microweber prior to 1.2.11.

CVE-2022-40129
Foxit Reader Web
8.8
HIGH
EPSS
0.7%
2022 CWE-416 1 PoC

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. A specially-crafted PDF document can trigger the reuse of previously freed memory via misusing Optional Content Group API, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CVE-2022-0523
radareorg/radare2 General
8.8
HIGH
EPSS
0.2%
2022 CWE-416 1 PoC

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

CVE-2022-20921
Cisco ACI Multi-Site Orchestrator Software Web Networking
8.8
HIGH
EPSS
0.5%
2022 CWE-285 1 PoC

A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker could exploit this vulnerability by sending crafted HTTP requests. A successful exploit could allow an attacker who is authenticated with non-Administrator privileges to elevate to Administrator privileges on an affected device.

CVE-2022-22994
My Cloud Web Cloud
8.8
HIGH
EPSS
0.8%
2022 CWE-345 1 PoC

A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an attacker could trick a NAS device into loading through an unsecured HTTP call. This was a result insufficient verification of calls to the device. The vulnerability was addressed by disabling checks for internet connectivity using HTTP.

CVE-2022-4230
WP Statistics Web Database Windows
8.8
HIGH
EPSS
1.4%
2022 1 PoC

The WP Statistics WordPress plugin before 13.2.9 does not escape a parameter, which could allow authenticated users to perform SQL Injection attacks. By default, the affected feature is available to users with the manage_options capability (admin+), however the plugin has a settings to allow low privilege users to access it as well.

CVE-2022-28763
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Windows
8.8
HIGH
EPSS
0.9%
2022 CWE-20 1 PoC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.12.2 is susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including session takeovers.

CVE-2022-2505
Firefox ESR General
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.1, Firefox < 103, and Thunderbird < 102.1.

CVE-2022-22113
DaybydayCRM General
8.8
HIGH
EPSS
0.3%
2022 CWE-613 1 PoC

In DayByDay CRM, versions 2.2.0 through 2.2.1 (latest) are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.