764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-47966
🔥 KEV Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 11 PoCs

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control

CVE-2022-37056
Software Genérico General
9.8
CRITICAL
EPSS
20.2%
2022 CWE-78 2 PoCs

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

CVE-2022-32224
https://github.com/rails/rails Web Database
9.8
CRITICAL
EPSS
1.9%
2022 CWE-502 1 PoC

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

CVE-2022-26258
🔥 KEV Software Genérico Web
9.8
CRITICAL
EPSS
87.2%
2022 2 PoCs

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

CVE-2022-24627
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
48.7%
2022 0 PoCs

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

CVE-2022-44252
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

CVE-2022-32588
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the PICT parsing pctwread_14841 functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-26318
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
92.2%
2022 5 PoCs

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVE-2022-46887
Software Genérico Web Database
9.8
CRITICAL
EPSS
2.8%
2022 1 PoC

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.

CVE-2022-30690
AVideo Web
9.6
CRITICAL
EPSS
9.8%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-41654
Ghost Web
9.6
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

An authentication bypass vulnerability exists in the newsletter subscription functionality of Ghost Foundation Ghost 5.9.4. A specially-crafted HTTP request can lead to increased privileges. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-22759
Firefox Web
9.6
CRITICAL
EPSS
0.3%
2022 2 PoCs

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-2733
openemr/openemr Web ⚡ nuclei
9.6
CRITICAL
EPSS
91.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-32772
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
7.8%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "msg" parameter which is inserted into the document with insufficient sanitization.

CVE-2022-26346
LinkHub Mesh Wifi Cloud
9.6
CRITICAL
EPSS
0.4%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the ucloud_del_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-24025
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the sntp binary.

CVE-2022-24005
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the ap_steer binary.

CVE-2022-24027
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the libcommon.so binary.

CVE-2022-24024
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the rtk_ate binary.

CVE-2022-32770
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
14.4%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "toast" parameter which is inserted into the document with insufficient sanitization.