2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-47859
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.

CVE-2022-4357
LetsRecover Web Database Windows
9.8
CRITICAL
EPSS
2.1%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-44283
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

CVE-2022-31706
vRealize Log Insight (vRLI) General ⚡ nuclei
9.8
CRITICAL
EPSS
90.2%
2022 1 PoC

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

CVE-2022-46583
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

CVE-2022-22954
🔥 KEV VMware Workspace ONE Access and Identity Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 36 PoCs

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVE-2022-4445
FL3R FeelBox Web Database Windows
9.8
CRITICAL
EPSS
4.7%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-45047
Apache MINA SSHD Web Networking
9.8
CRITICAL
EPSS
5.7%
2022 CWE-502 1 PoC

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CVE-2022-35244
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
0.7%
2022 CWE-134 1 PoC

A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-41837
OpenImageIO General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-562 1 PoC

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-44938
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

CVE-2022-46366
Apache Tapestry Web
9.8
CRITICAL
EPSS
3.9%
2022 CWE-502 2 PoCs

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

CVE-2022-27805
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
1.3%
2022 CWE-284 1 PoC

An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted network request can lead to arbitrary XCMD execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-46291
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MSI file format

CVE-2022-46637
Software Genérico Networking
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP services.

CVE-2022-25767
com.bstek.ureport:ureport2-console General
9.8
CRITICAL
EPSS
3.1%
2022 1 PoC

All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.

CVE-2022-43019
Software Genérico General
9.8
CRITICAL
EPSS
16.4%
2022 1 PoC

OpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.

CVE-2022-21165
font-converter General
9.8
CRITICAL
EPSS
2.6%
2022 1 PoC

All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.

CVE-2022-43212
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

CVE-2022-34487
Shortcode Addons (WordPress plugin) Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
42.5%
2022 CWE-264 0 PoCs

Unauthenticated Arbitrary Option Update vulnerability in biplob018's Shortcode Addons plugin <= 3.0.2 at WordPress.