2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46914
Software Genérico General
8.8
HIGH
EPSS
0.7%
2022 2 PoCs

An issue in the firmware update process of TP-LINK TL-WA801N / TL-WA801ND V1 v3.12.16 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVE-2022-42139
Software Genérico General
8.8
HIGH
EPSS
22.6%
2022 1 PoC

Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

CVE-2022-1329
Elementor Website Builder Web Windows ⚡ nuclei
8.8
HIGH
EPSS
93.4%
2022 CWE-862 8 PoCs

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

CVE-2022-46699
tvOS General
8.8
HIGH
EPSS
0.5%
2022 5 PoCs

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-24388
Fidelis Network General
8.8
HIGH
EPSS
0.9%
2022 CWE-78 1 PoC

Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.4.5. Patches and updates are available to address this vulnerability.

CVE-2022-48194
Software Genérico General
8.8
HIGH
EPSS
55.5%
2022 1 PoC

TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

CVE-2022-28751
Zoom Client for Meetings for MacOS General
8.8
HIGH
EPSS
0.0%
2022 CWE-347 1 PoC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-48592
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-45030
Software Genérico Web Database
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).

CVE-2022-40127
Apache Airflow Web ⚡ nuclei
8.8
HIGH
EPSS
93.3%
2022 CWE-94 3 PoCs

A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

CVE-2022-47542
Software Genérico Database
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

CVE-2022-21510
Database - Enterprise Edition Database
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Oracle Database - Enterprise Edition Sharding executes to compromise Oracle Database - Enterprise Edition Sharding. While the vulnerability is in Oracle Database - Enterprise Edition Sharding, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

CVE-2022-3494
Complianz – GDPR/CCPA Cookie Consent Web Database Windows
8.8
HIGH
EPSS
1.0%
2022 CWE-89 1 PoC

The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.

CVE-2022-3918
Swift Foundation Web
8.8
HIGH
EPSS
0.4%
2022 1 PoC

A program using FoundationNetworking in swift-corelibs-foundation is potentially vulnerable to CRLF ( ) injection in URLRequest headers. In this vulnerability, a client can insert one or several CRLF sequences into a URLRequest header value. When that request is sent via URLSession to an HTTP server, the server may interpret the content after the CRLF as extra headers, or even a second request. For example, consider a URLRequest to http://example.com/ with the GET method. Suppose we set the URLRequest header "Foo" to the value "Bar Extra-Header: Added GET /other HTTP/1.1". When this request is

CVE-2022-4505
openemr/openemr General
8.8
HIGH
EPSS
0.5%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-24384
SmarterTrack Web ⚡ nuclei
8.8
HIGH
EPSS
48.0%
2022 CWE-79 0 PoCs

Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.

CVE-2022-42719
Software Genérico General
8.8
HIGH
EPSS
0.6%
2022 2 PoCs

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

CVE-2022-0511
Firefox General
8.8
HIGH
EPSS
0.4%
2022 1 PoC

Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97.