764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-44191
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameters KEY1 and KEY2.

CVE-2022-36320
Firefox General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.

CVE-2022-44929
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

CVE-2022-4693
User Verification Web Windows
9.8
CRITICAL
EPSS
10.2%
2022 1 PoC

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.

CVE-2022-44807
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

CVE-2022-46967
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.

CVE-2022-34718
Windows 10 Version 1809 Windows
9.8
CRITICAL
EPSS
85.8%
2022 1 PoC

Windows TCP/IP Remote Code Execution Vulnerability

CVE-2022-44801
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2022 1 PoC

D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

CVE-2022-23219
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

CVE-2022-47877
Software Genérico Web
9.6
CRITICAL
EPSS
8.0%
2022 1 PoC

A Stored cross-site scripting vulnerability in Jedox 2020.2.5 allows remote, authenticated users to inject arbitrary web script or HTML in the Logs page via the log module 'log'.

CVE-2022-21178
LinkHub Mesh Wifi Cloud
9.6
CRITICAL
EPSS
4.8%
2022 CWE-78 1 PoC

An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-32771
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
10.0%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.

CVE-2022-24010
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cwmpd binary.

CVE-2022-22114
docs Web
9.6
CRITICAL
EPSS
2.0%
2022 CWE-79 1 PoC

In Teedy, versions v1.5 through v1.9 are vulnerable to Reflected Cross-Site Scripting (XSS). The “search term" search functionality is not sufficiently sanitized while displaying the results of the search, which can be leveraged to inject arbitrary scripts. These scripts are executed in a victim’s browser when they enter the crafted URL. In the worst case, the victim who inadvertently triggers the attack is a highly privileged administrator. The injected scripts can extract the Session ID, which can lead to full Account Takeover of the administrator, by an unauthenticated attacker.

CVE-2022-24007
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cfm binary.

CVE-2022-24014
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the logserver binary.

CVE-2022-0173
radareorg/radare2 General
9.6
CRITICAL
EPSS
0.4%
2022 CWE-125 1 PoC

radare2 is vulnerable to Out-of-bounds Read

CVE-2022-24013
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the gpio_ctrl binary.

CVE-2022-30584
Software Genérico General
9.6
CRITICAL
EPSS
0.5%
2022 1 PoC

Archer Platform 6.3 before 6.11 (6.11.0.0) contains an Improper Access Control Vulnerability within SSO ADFS functionality that could potentially be exploited by malicious users to compromise the affected system. 6.10 P3 (6.10.0.3) and 6.9 SP3 P4 (6.9.3.4) are also fixed releases.

CVE-2022-24017
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the miniupnpd binary.