2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-43216
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2022 1 PoC

AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

CVE-2022-29830
GX Works3 Cloud
9.1
CRITICAL
EPSS
1.2%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthenticated attackers may obtain information about project files illegally.

CVE-2022-37337
Orbi Router RBR750 Web Networking
9.1
CRITICAL
EPSS
0.7%
2022 CWE-78 3 PoCs

A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-26007
InRouter302 Networking
9.1
CRITICAL
EPSS
3.5%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-32763
lansweeper Web
9.1
CRITICAL
EPSS
0.9%
2022 CWE-184 1 PoC

A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-25784
SiteManager Web
9.1
CRITICAL
EPSS
0.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) vulnerability in Web GUI of SiteManager allows logged-in user to inject scripting. This issue affects: Secomea SiteManager all versions prior to 9.7.

CVE-2022-45891
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).

CVE-2022-40842
Software Genérico Web
9.1
CRITICAL
EPSS
0.7%
2022 1 PoC

ndk design NdkAdvancedCustomizationFields 3.5.0 is vulnerable to Server-side request forgery (SSRF) via rotateimg.php.

CVE-2022-3782
Keycloak General
9.1
CRITICAL
EPSS
0.1%
2022 1 PoC

keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

CVE-2022-21217
Software Genérico Web
9.1
CRITICAL
EPSS
0.4%
2022 CWE-457 1 PoC

An out-of-bounds write vulnerability exists in the device TestEmail functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted network request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-1399
CMDB General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-88 1 PoC

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-27498
lansweeper Web
9.1
CRITICAL
EPSS
44.7%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the TicketTemplateActions.aspx GetTemplateAttachment functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-33326
R1510 Web
9.1
CRITICAL
EPSS
3.5%
2022 CWE-78 1 PoC

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/config_rollback/` API is affected by a command injection vulnerability.

CVE-2022-26851
PowerScale OneFS General
9.1
CRITICAL
EPSS
0.4%
2022 CWE-330 1 PoC

Dell PowerScale OneFS, 8.2.2-9.3.x, contains a predictable file name from observable state vulnerability. An unprivileged network attacker could potentially exploit this vulnerability, leading to data loss.

CVE-2022-36323
RUGGEDCOM RM1224 LTE(4G) EU General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-74 1 PoC

Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject code or spawn a system root shell.

CVE-2022-22149
lansweeper Web Database
9.1
CRITICAL
EPSS
7.0%
2022 CWE-89 2 PoCs

A SQL injection vulnerability exists in the HelpdeskEmailActions.aspx functionality of Lansweeper lansweeper 9.1.20.2. A specially-crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-24856
flyteconsole General ⚡ nuclei
9.1
CRITICAL
EPSS
81.9%
2022 CWE-918 0 PoCs

FlyteConsole is the web user interface for the Flyte platform. FlyteConsole prior to version 0.52.0 is vulnerable to server-side request forgery (SSRF) when FlyteConsole is open to the general internet. An attacker can exploit any user of a vulnerable instance to access the internal metadata server or other unauthenticated URLs. Passing of headers to an unauthorized actor may occur. The patch for this issue deletes the entire `cors_proxy`, as this is not required for console anymore. A patch is available in FlyteConsole version 0.52.0. Disable FlyteConsole availability on the internet as a wor

CVE-2022-46836
Checkmk Web
9.1
CRITICAL
EPSS
2.1%
2022 CWE-20 1 PoC

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

CVE-2022-29511
lansweeper Web
9.1
CRITICAL
EPSS
16.6%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the KnowledgebasePageActions.aspx ImportArticles functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-0742
Kernel General
9.1
CRITICAL
EPSS
2.2%
2022 CWE-275 1 PoC

Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc.