764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2734
openemr/openemr General
10.0
CRITICAL
EPSS
1.0%
2022 CWE-1021 1 PoC

Improper Restriction of Rendered UI Layers or Frames in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-20712
Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
2.2%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-20701
🔥 KEV Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
6.1%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-33195
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
4.8%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_DefaultKeyID` in the function located at offset `0x1c7d28` of firmware 6.9Z, and even more specifically on the command execution occuring at offset `0x1c7fac`.

CVE-2022-2310
Skyhigh Secure Web Gateway (SWG) General
10.0
CRITICAL
EPSS
1.4%
2022 CWE-290 1 PoC

An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super u

CVE-2022-33194
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
3.6%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `WL_Key` and `WL_DefaultKeyID` configuration values in the function located at offset `0x1c7d28` of firmware 6.9Z , and even more specifically on the command execution occuring at offset `0x1c7f6c`.

CVE-2022-36067
vm2 General
10.0
CRITICAL
EPSS
82.5%
2022 CWE-913 3 PoCs

vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox. This vulnerability was patched in the release of version 3.9.11 of vm2. There are no known workarounds.

CVE-2022-32548
Software Genérico Networking
10.0
CRITICAL
EPSS
65.6%
2022 6 PoCs

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

CVE-2022-24816
🔥 KEV jai-ext Web ⚡ nuclei
10.0
CRITICAL
EPSS
93.7%
2022 CWE-94 1 PoC

JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java code via Janino, and executed. In particular, this affects the downstream GeoServer project. Version 1.2.22 will contain a patch that disables the ability to inject malicious code into the resulting script. Users unable to upgrade may negate the ability to compile Jiffle scripts from the final application, by removing janino-x.y.z.jar from the classpath.

CVE-2022-43605
OpENer General
10.0
CRITICAL
EPSS
5.5%
2022 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the SetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out of bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVE-2022-29472
iota All-In-One Security Kit Web
10.0
CRITICAL
EPSS
4.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-22995
My Cloud Cloud Windows
10.0
CRITICAL
EPSS
0.2%
2022 CWE-59 1 PoC

The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.

CVE-2022-32454
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
5.0%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the XCMD setIPCam functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to remote code execution. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-20707
Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
81.4%
2022 CWE-121 2 PoCs

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-2023
polonel/trudesk Web
10.0
CRITICAL
EPSS
0.4%
2022 CWE-648 1 PoC

Incorrect Use of Privileged APIs in GitHub repository polonel/trudesk prior to 1.2.4.

CVE-2022-20704
Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
0.9%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-1531
rtxteam/rtx Database
10.0
CRITICAL
EPSS
3.8%
2022 CWE-89 1 PoC

SQL injection vulnerability in ARAX-UI Synonym Lookup functionality in GitHub repository rtxteam/rtx prior to checkpoint_2022-04-20 . This vulnerability is critical as it can lead to remote code execution and thus complete server takeover.

CVE-2022-21806
Eufy Homebase 2 General
10.0
CRITICAL
EPSS
1.8%
2022 CWE-368 1 PoC

A use-after-free vulnerability exists in the mips_collector appsrv_server functionality of Anker Eufy Homebase 2 2.1.8.5h. A specially-crafted set of network packets can lead to remote code execution. The device is exposed to attacks from the network.

CVE-2022-31125
roxy-wi Web
10.0
CRITICAL
EPSS
18.2%
2022 CWE-287 1 PoC

Roxy-wi is an open source web interface for managing Haproxy, Nginx, Apache and Keepalived servers. A vulnerability in Roxy-wi allows a remote, unauthenticated attacker to bypass authentication and access admin functionality by sending a specially crafted HTTP request. This affects Roxywi versions before 6.1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.

CVE-2022-33206
iota All-In-One Security Kit Web
10.0
CRITICAL
EPSS
4.7%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on the unsafe use of the `key` and `default_key_id` HTTP parameters to construct an OS Command crafted at offset `0x19b1f4` of the `/root/hpgw` binary included in firmware 6.9Z.