5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0868
medialize/uri.js General
8.0
HIGH
EPSS
0.3%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

CVE-2022-2487
WN535K2 General ⚡ nuclei
8.0
HIGH
EPSS
93.1%
2022 CWE-78 1 PoC

A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection. The exploit has been disclosed to the public and may be used.

CVE-2022-29841
My Cloud OS 5 Cloud
8.0
HIGH
EPSS
0.4%
2022 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data. This command could be triggered by an attacker remotely to cause code execution and gain a reverse shell in Western Digital My Cloud OS 5 devices.This issue affects My Cloud OS 5: before 5.26.119.

CVE-2022-2486
WN535K2 General ⚡ nuclei
8.0
HIGH
EPSS
91.0%
2022 CWE-78 1 PoC

A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The exploit has been disclosed to the public and may be used.

CVE-2022-45938
Software Genérico Web
8.0
HIGH
EPSS
21.1%
2022 1 PoC

An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..

CVE-2022-39290
zoneminder Web
8.0
HIGH
EPSS
4.0%
2022 CWE-287 1 PoC

ZoneMinder is a free, open source Closed-circuit television software application. In affected versions authenticated users can bypass CSRF keys by modifying the request supplied to the Zoneminder web application. These modifications include replacing HTTP POST with an HTTP GET and removing the CSRF key from the request. An attacker can take advantage of this by using an HTTP GET request to perform actions with no CSRF protection. This could allow an attacker to cause an authenticated user to perform unexpected actions on the web application. Users are advised to upgrade as soon as possible. Th

CVE-2022-21934
Metasys ADS/ADX/OAS server General
8.0
HIGH
EPSS
0.3%
2022 CWE-620 1 PoC

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.

CVE-2022-2027
kromitgmbh/titra General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Improper Neutralization of Formula Elements in a CSV File in GitHub repository kromitgmbh/titra prior to 0.77.0.

CVE-2022-30577
TIBCO EBX Web
8.0
HIGH
EPSS
0.9%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO EBX contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO EBX: versions 6.0.0 through 6.0.8.

CVE-2022-40472
Software Genérico Cloud
8.0
HIGH
EPSS
0.7%
2022 1 PoC

ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.

CVE-2022-39950
Fortinet FortiAnalyzer, FortiManager Web Networking
8.0
HIGH
EPSS
0.7%
2022 1 PoC

An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege level attacker to perform an XSS attack via posting a crafted CKeditor "protected" comment as described in CVE-2020-9281.

CVE-2022-2420
Web Manager Web
8.0
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in URVE Web Manager. It has been rated as critical. This issue affects some unknown processing of the file _internal/uploader.php. The manipulation leads to unrestricted upload. The attack needs to be approached within the local network. The exploit has been disclosed to the public and may be used.

CVE-2022-33936
Cloud Mobility for Dell Storage Cloud
8.0
HIGH
EPSS
0.4%
2022 1 PoC

Cloud Mobility for Dell EMC Storage, 1.3.0.XXX contains a RCE vulnerability. A non-privileged user could potentially exploit this vulnerability, leading to achieving a root shell. This is a critical issue; so Dell recommends customers to upgrade at the earliest opportunity.

CVE-2022-2418
Web Manager Web
8.0
HIGH
EPSS
0.3%
2022 CWE-434 1 PoC

A vulnerability was found in URVE Web Manager. It has been classified as critical. This affects an unknown part of the file kreator.html5/img_upload.php. The manipulation leads to unrestricted upload. Access to the local network is required for this attack. The exploit has been disclosed to the public and may be used.

CVE-2022-1410
CMDB General
8.0
HIGH
EPSS
1.2%
2022 CWE-78 1 PoC

OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-3558
Import and export users and customers Web Windows
8.0
HIGH
EPSS
0.8%
2022 CWE-1236 1 PoC

The Import and export users and customers WordPress plugin before 1.20.5 does not properly escape data when exporting it via CSV files.

CVE-2022-27647
R6700v3 Networking Cloud
8.0
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the handling of the name or email field provided to libreadycloud.so. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15874.

CVE-2022-22776
TIBCO BusinessConnect Trading Community Management Web
8.0
HIGH
EPSS
0.6%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management contains easily exploitable vulnerabilities that allows a low privileged attacker with network access to execute Stored Cross Site Scripting (XSS) on the affected system. A successful attack using these vulnerabilities requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO BusinessConnect Trading Community Management: versions 6.1.0 and below.

CVE-2022-0155
follow-redirects/follow-redirects General
8.0
HIGH
EPSS
1.3%
2022 CWE-359 1 PoC

follow-redirects is vulnerable to Exposure of Private Personal Information to an Unauthorized Actor

CVE-2022-4815
Pentaho Business Analytics Server General
8.0
HIGH
EPSS
0.5%
2022 CWE-502 1 PoC

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.