764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46353
SCALANCE X204RNA (HSR) General
9.8
CRITICAL
EPSS
2.0%
2022 CWE-330 1 PoC

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The webserver of affected devices calculates session ids and nonces in an insecure manner. This could allow an unauthenticated remote attacker to brute-force session ids and hijack existing sessions.

CVE-2022-47003
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
24.4%
2022 0 PoCs

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

CVE-2022-34668
NVIDIA FLARE General
9.8
CRITICAL
EPSS
22.4%
2022 CWE-502 1 PoC

NVFLARE, versions prior to 2.1.4, contains a vulnerability that deserialization of Untrusted Data due to Pickle usage may allow an unprivileged network attacker to cause Remote Code Execution, Denial Of Service, and Impact to both Confidentiality and Integrity.

CVE-2022-45933
Software Genérico DevOps Web ⚡ nuclei
9.8
CRITICAL
EPSS
93.2%
2022 0 PoCs

KubeView through 0.1.31 allows attackers to obtain control of a Kubernetes cluster because api/scrape/kube-system does not require authentication, and retrieves certificate files that can be used for authentication as kube-admin. NOTE: the vendor's position is that KubeView was a "fun side project and a learning exercise," and not "very secure."

CVE-2022-46169
🔥 KEV cacti Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-74 40 PoCs

Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyadd

CVE-2022-40872
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

An SQL injection vulnerability issue was discovered in Sourcecodester Simple E-Learning System 1.0., in /vcs/classRoom.php?classCode=, classCode.

CVE-2022-47714
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Last Yard 22.09.8-1 does not enforce HSTS headers

CVE-2022-3236
🔥 KEV Sophos Firewall Networking ⚡ nuclei
9.8
CRITICAL
EPSS
92.8%
2022 0 PoCs

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-45136
Apache Jena SDB Web Database
9.8
CRITICAL
EPSS
2.0%
2022 CWE-502 1 PoC

Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of attack. As a result an application using Apache Jena SDB can be subject to RCE when connected to a malicious database server. Apache Jena SDB has been EOL since December 2020 and users should migrate to alternative options e.g. Apache Jena TDB 2.

CVE-2022-33174
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
72.0%
2022 2 PoCs

Power Distribution Units running on Powertek firmware (multiple brands) before 3.30.30 allows remote authorization bypass in the web interface. To exploit the vulnerability, an attacker must send an HTTP packet to the data retrieval interface (/cgi/get_param.cgi) with the tmpToken cookie set to an empty string followed by a semicolon. This bypasses an active session authorization check. This can be then used to fetch the values of protected sys.passwd and sys.su.name fields that contain the username and password in cleartext.

CVE-2022-4297
WP AutoComplete Search Web Database Windows
9.8
CRITICAL
EPSS
3.1%
2022 2 PoCs

The WP AutoComplete Search WordPress plugin through 1.0.4 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX available to unauthenticated users, leading to an unauthenticated SQL injection

CVE-2022-43109
Software Genérico General
9.8
CRITICAL
EPSS
8.0%
2022 1 PoC

D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.

CVE-2022-47770
Software Genérico Database
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Serenissima Informatica Fast Checkin version v1.0 is vulnerable to Unauthenticated SQL Injection.

CVE-2022-2631
tooljet/tooljet General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

Improper Access Control in GitHub repository tooljet/tooljet prior to v1.19.0.

CVE-2022-40684
🔥 KEV Fortinet FortiOS, FortiProxy, FortiSwitchManager Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 27 PoCs

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.

CVE-2022-20472
Android General
9.8
CRITICAL
EPSS
4.5%
2022 1 PoC

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239210579

CVE-2022-37204
Software Genérico Web Database
9.8
CRITICAL
EPSS
1.1%
2022 2 PoCs

Final CMS 5.1.0 is vulnerable to SQL Injection.

CVE-2022-22770
TIBCO AuditSafe Web
9.8
CRITICAL
EPSS
1.9%
2022 1 PoC

The Web Server component of TIBCO Software Inc.'s TIBCO AuditSafe contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute API methods on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO AuditSafe: versions 1.1.0 and below.

CVE-2022-3600
Easy Digital Downloads Web Windows
9.8
CRITICAL
EPSS
1.3%
2022 1 PoC

The Easy Digital Downloads WordPress plugin before 3.1.0.2 does not validate data when its output in a CSV file, which could lead to CSV injection.

CVE-2022-26112
Apache Pinot Web
9.8
CRITICAL
EPSS
1.9%
2022 1 PoC

In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0