163 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-31126
roxy-wi Web ⚡ nuclei
10.0
CRITICAL
EPSS
89.1%
2022 CWE-74 0 PoCs

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to code execution by sending a specially crafted HTTP request to /app/options.py file. This affects Roxy-wi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-27593
🔥 KEV Photo Station General ⚡ nuclei
10.0
CRITICAL
EPSS
93.1%
2022 CWE-610 0 PoCs

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CVE-2022-31161
roxy-wi Web ⚡ nuclei
10.0
CRITICAL
EPSS
73.0%
2022 CWE-77 1 PoC

Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Version 6.1.1.0 contains a patch for this issue.

CVE-2022-22947
🔥 KEV Spring Cloud Gateway Web Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.5%
2022 CWE-94 76 PoCs

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

CVE-2022-31137
roxy-wi Web ⚡ nuclei
10.0
CRITICAL
EPSS
94.0%
2022 CWE-78 4 PoCs

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Versions prior to 6.1.1.0 are subject to a remote code execution vulnerability. System commands can be run remotely via the subprocess_execute function without processing the inputs received from the user in the /app/options.py file. Attackers need not be authenticated to exploit this vulnerability. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2022-24816
🔥 KEV jai-ext Web ⚡ nuclei
10.0
CRITICAL
EPSS
93.7%
2022 CWE-94 1 PoC

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

CVE-2022-0735
GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
57.4%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVE-2022-44588
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.9
CRITICAL
EPSS
34.7%
2022 CWE-89 0 PoCs

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

CVE-2022-45808
LearnPress – WordPress LMS Plugin Web Database Windows ⚡ nuclei
9.9
CRITICAL
EPSS
83.6%
2022 CWE-89 1 PoC

SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

CVE-2022-2185
GitLab DevOps ⚡ nuclei
9.9
CRITICAL
EPSS
90.1%
2022 3 PoCs

A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously crafted project leading to remote code execution.

CVE-2022-24900
Piano-LED-Visualizer General ⚡ nuclei
9.9
CRITICAL
EPSS
73.3%
2022 CWE-73 0 PoCs

Piano LED Visualizer is software that allows LED lights to light up as a person plays a piano connected to a computer. Version 1.3 and prior are vulnerable to a path traversal attack. The `os.path.join` call is unsafe for use with untrusted input. When the `os.path.join` call encounters an absolute path, it ignores all the parameters it has encountered till that point and starts working with the new absolute path. Since the "malicious" parameter represents an absolute path, the result of `os.path.join` ignores the static directory completely. Hence, untrusted input is passed via the `os.path.j

CVE-2022-0415
gogs/gogs General ⚡ nuclei
9.9
CRITICAL
EPSS
89.6%
2022 CWE-20 1 PoC

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

CVE-2022-1609
school-management-pro Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2022 10 PoCs

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

CVE-2022-29464
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 50 PoCs

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and

CVE-2022-4059
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
56.6%
2022 1 PoC

The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-38627
Software Genérico Database ⚡ nuclei
9.8
CRITICAL
EPSS
76.2%
2022 2 PoCs

Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.

CVE-2022-40022
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
90.8%
2022 2 PoCs

Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability.

CVE-2022-42149
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
42.8%
2022 0 PoCs

kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.

CVE-2022-0342
USG/ZyWALL series firmware Networking ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2022 CWE-287 0 PoCs

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

CVE-2022-45699
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
90.0%
2022 1 PoC

Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.