5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30216
Windows 10 Version 21H1 Windows
8.8
HIGH
EPSS
59.6%
2022 1 PoC

Windows Server Service Tampering Vulnerability

CVE-2022-32507
Software Genérico General
8.8
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

CVE-2022-0664
gravitl/netmaker General
8.8
HIGH
EPSS
0.3%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.

CVE-2022-28802
Software Genérico Web
8.8
HIGH
EPSS
0.7%
2022 1 PoC

Code by Zapier before 2022-08-17 allowed intra-account privilege escalation that included execution of Python or JavaScript code. In other words, Code by Zapier was providing a customer-controlled general-purpose virtual machine that unintentionally granted full access to all users of a company's account, but was supposed to enforce role-based access control within that company's account. Before 2022-08-17, a customer could have resolved this by (in effect) using a separate virtual machine for an application that held credentials - or other secrets - that weren't supposed to be shared among al

CVE-2022-23918
LinkHub Mesh Wifi General
8.8
HIGH
EPSS
0.5%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability leverages the ethAddr field within the protobuf message to cause a buffer overflow.

CVE-2022-29557
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 1 PoC

LexisNexis Firco Compliance Link 3.7 allows CSRF.

CVE-2022-22026
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
0.5%
2022 1 PoC

Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability

CVE-2022-43654
CAX30S Web Networking
8.8
HIGH
EPSS
2.7%
2022 CWE-78 1 PoC

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the token parameter provided to the sso.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18227.

CVE-2022-4223
pgadmin4 Web Database Windows ⚡ nuclei
8.8
HIGH
EPSS
87.8%
2022 CWE-94 0 PoCs

The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin prior to 6.17 failed to properly secure this API, which could allow an unauthenticated user to call it with a path of their choosing, such as a UNC path to a server they control on a Windows machine. This would cause an appropriately named executable in the target path to be executed by the pgAdmin server.

CVE-2022-3395
WP All Export Pro Web Database Windows
8.8
HIGH
EPSS
0.7%
2022 CWE-89 1 PoC

The WP All Export Pro WordPress plugin before 1.7.9 uses the contents of the cc_sql POST parameter directly as a database query, allowing users which has been given permission to run exports to execute arbitrary SQL statements, leading to a SQL Injection vulnerability. By default only users with the Administrator role can perform exports, but this can be delegated to lower privileged users as well.

CVE-2022-38841
Software Genérico General
8.8
HIGH
EPSS
16.6%
2022 1 PoC

Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

CVE-2022-22778
TIBCO BusinessConnect Trading Community Management Web
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute Cross-Site Request Forgery (CSRF) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

CVE-2022-21613
Enterprise Data Quality Web Database
8.8
HIGH
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Enterprise Data Quality product of Oracle Fusion Middleware (component: Dashboard). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Data Quality. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Data Quality, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unautho

CVE-2022-44254
Software Genérico General
8.8
HIGH
EPSS
0.7%
2022 1 PoC

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter text in the setSmsCfg function.

CVE-2022-37155
Software Genérico General
8.8
HIGH
EPSS
6.2%
2022 2 PoCs

RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.

CVE-2022-30165
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
7.4%
2022 1 PoC

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2022-37208
Software Genérico Web Database
8.8
HIGH
EPSS
1.1%
2022 1 PoC

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-32893
🔥 KEV Safari General
8.8
HIGH
EPSS
0.2%
2022 4 PoCs

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2022-44258
Software Genérico General
8.8
HIGH
EPSS
0.7%
2022 1 PoC

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter command in the setTracerouteCfg function.

CVE-2022-25766
ungit Web
8.8
HIGH
EPSS
4.2%
2022 1 PoC

The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled values (remote and ref) are passed to the git fetch command. By injecting some git options it was possible to get arbitrary command execution.