2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-40944
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.7%
2022 3 PoCs

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via sales-report-ds.php file.

CVE-2022-43999
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

CVE-2022-39184
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.

CVE-2022-36934
WhatsApp for iOS General
9.8
CRITICAL
EPSS
12.7%
2022 CWE-122 1 PoC

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVE-2022-4049
WP User Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
66.6%
2022 1 PoC

The WP User WordPress plugin through 7.0 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users.

CVE-2022-41639
OpenImageIO General
9.8
CRITICAL
EPSS
0.8%
2022 CWE-122 1 PoC

A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-47036
Software Genérico General
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

Siklu TG Terragraph devices before approximately 2.1.1 have a hardcoded root password that has been revealed via a brute force attack on an MD5 hash. It can be used for "debug login" by an admin. NOTE: the vulnerability is not fixed by the 2.1.1 firmware; instead, it is fixed in newer hardware, which would typically be used with firmware 2.1.1 or later.

CVE-2022-36231
Software Genérico General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.

CVE-2022-41220
Software Genérico General
9.8
CRITICAL
EPSS
12.6%
2022 1 PoC

md2roff 1.9 has a stack-based buffer overflow via a Markdown file, a different vulnerability than CVE-2022-34913. NOTE: the vendor's position is that the product is not intended for untrusted input

CVE-2022-4939
WCFM Membership – WooCommerce Memberships for Multivendor Marketplace Web Windows
9.8
CRITICAL
EPSS
20.3%
2022 CWE-862 1 PoC

THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including 2.10.0, due to a missing capability check on the wp_ajax_nopriv_wcfm_ajax_controller AJAX action that controls membership settings. This makes it possible for unauthenticated attackers to modify the membership registration form in a way that allows them to set the role for registration to that of any user including administrators. Once configured, the attacker can then register as an administrator.

CVE-2022-26352
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 2 PoCs

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

CVE-2022-4681
Hide My WP Web Database Windows
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-46599
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setlogo_num parameter in the icp_setlogo_img (sub_41DBF4) function.

CVE-2022-23218
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

CVE-2022-43000
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep4_pskpwd parameter at /goform/form2WizardStep4.

CVE-2022-47121
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey parameter at /goform/WifiBasicSet.

CVE-2022-46294
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC Cartesian file format

CVE-2022-3603
Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list Web Windows
9.8
CRITICAL
EPSS
2.0%
2022 1 PoC

The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list WordPress plugin before 2.0.69 does not validate data when outputting it back in a CSV file, which could lead to CSV injection.

CVE-2022-1715
neorazorx/facturascripts General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-1125 1 PoC

Account Takeover in GitHub repository neorazorx/facturascripts prior to 2022.07.