2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-24082
Pega Infinity Cloud
9.8
CRITICAL
EPSS
45.6%
2022 CWE-502 1 PoC

If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it may be possible to upload serialized payloads to attack the underlying system. This does not affect systems running on PegaCloud due to its design and architecture.

CVE-2022-45173
Software Genérico Web
9.8
CRITICAL
EPSS
0.1%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk through v018. A Bypass of Two-Factor Authentication can occur under the /api/v1/vdeskintegration/challenge endpoint. Because only the client-side verifies whether a check was successful, an attacker can modify the response, and fool the application into concluding that the TOTP was correct.

CVE-2022-45477
Telepad General
9.8
CRITICAL
EPSS
9.5%
2022 CWE-306 1 PoC

Telepad allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-31736
Thunderbird General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

A malicious website could have learned the size of a cross-origin resource that supported Range requests. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVE-2022-40089
Software Genérico Web
9.8
CRITICAL
EPSS
2.9%
2022 3 PoCs

A remote file inclusion (RFI) vulnerability in Simple College Website v1.0 allows attackers to execute arbitrary code via a crafted PHP file. This vulnerability is exploitable when the directive allow_url_include is set to On.

CVE-2022-29464
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 50 PoCs

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and

CVE-2022-33321
PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE PV-DR006L-SET-M Web
9.8
CRITICAL
EPSS
0.8%
2022 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unaut

CVE-2022-40055
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

An issue in GX Group GPON ONT Titanium 2122A T2122-V1.26EXL allows attackers to escalate privileges via a brute force attack at the login page.

CVE-2022-0547
OpenVPN Networking
9.8
CRITICAL
EPSS
0.5%
2022 CWE-305 1 PoC

OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be granted access with only partially correct credentials.

CVE-2022-44191
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

CVE-2022-4059
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
56.6%
2022 1 PoC

The Cryptocurrency Widgets Pack WordPress plugin before 2.0 does not sanitise and escape some parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-44151
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php.

CVE-2022-43213
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.

CVE-2022-47769
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

CVE-2022-27518
🔥 KEV Citrix Gateway, Citrix ADC Networking
9.8
CRITICAL
EPSS
27.7%
2022 CWE-664 1 PoC

Unauthenticated remote arbitrary code execution

CVE-2022-44262
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2022 2 PoCs

ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

CVE-2022-4851
usememos/memos General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-229 1 PoC

Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-39185
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

CVE-2022-3921
Listingo Web Windows
9.8
CRITICAL
EPSS
7.8%
2022 1 PoC

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE