764 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-50691
MiniDVBLinux General
9.3
CRITICAL
EPSS
0.4%
2022 CWE-78 1 PoC

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands.sh endpoint by sending malicious command values to gain root-level system access.

CVE-2022-33965
WP Visitor Statistics (WordPress plugin) Web Database Windows ⚡ nuclei
9.3
CRITICAL
EPSS
42.7%
2022 CWE-89 0 PoCs

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

CVE-2022-0990
janeczku/calibre-web General
9.3
CRITICAL
EPSS
0.3%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.

CVE-2022-3405
Acronis Cyber Protect 15 Windows
9.3
CRITICAL
EPSS
36.9%
2022 CWE-269 1 PoC

Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545.

CVE-2022-1212
mruby/mruby General
9.3
CRITICAL
EPSS
0.9%
2022 CWE-416 1 PoC

Use-After-Free in str_escape in mruby/mruby in GitHub repository mruby/mruby prior to 3.2. Possible arbitrary code execution if being exploited.

CVE-2022-50912
ImpressCMS Web
9.3
CRITICAL
EPSS
0.2%
2022 CWE-434 1 PoC

ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.

CVE-2022-50794
Impact/Pulse/First Web
9.3
CRITICAL
EPSS
1.7%
2022 CWE-78 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.

CVE-2022-50803
JF511-TV Networking
9.3
CRITICAL
EPSS
0.1%
2022 CWE-1392 1 PoC

JM-DATA ONU JF511-TV version 1.0.67 uses default credentials that allow attackers to gain unauthorized access to the device with administrative privileges.

CVE-2022-1996
emicklei/go-restful General
9.3
CRITICAL
EPSS
1.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVE-2022-21817
Software Genérico General
9.3
CRITICAL
EPSS
0.9%
2022 1 PoC

NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security domains, which may lead to code execution, escalation of privileges, and impact to confidentiality and integrity.

CVE-2022-4978
Remote Control Collection Server General
9.3
CRITICAL
EPSS
32.4%
2022 CWE-306 1 PoC

Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same network can issue a sequence of keystroke commands to launch a system shell and execute arbitrary commands, resulting in full system compromise.

CVE-2022-27185
LinkHub Mesh Wifi General
9.3
CRITICAL
EPSS
0.3%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_master_wlan functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-41559
TIBCO Nimbus General
9.3
CRITICAL
EPSS
1.0%
2022 1 PoC

The Web Client component of TIBCO Software Inc.'s TIBCO Nimbus contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to exploit an open redirect on the affected system. A successful attack using this vulnerability requires human interaction from a person other than the attacker. Affected releases are TIBCO Software Inc.'s TIBCO Nimbus: version 10.5.0.

CVE-2022-1543
erudika/scoold General
9.3
CRITICAL
EPSS
0.4%
2022 CWE-130 1 PoC

Improper handling of Length parameter in GitHub repository erudika/scoold prior to 1.49.4. When the text size is large enough the service results in a momentary outage in a production environment. That can lead to memory corruption on the server.

CVE-2022-1231
plantuml/plantuml Web
9.3
CRITICAL
EPSS
0.2%
2022 CWE-79 2 PoCs

XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected. Since the SVG format allows clickable links in diagrams, it is commonly used in plugins for web based projects (like the Confluence plugin, etc. see https://plantuml.com/de/running).

CVE-2022-21796
Software Genérico Web
9.3
CRITICAL
EPSS
0.7%
2022 CWE-20 1 PoC

A memory corruption vulnerability exists in the netserver parse_command_list functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to an out-of-bounds write. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-47615
LearnPress – WordPress LMS Plugin Web Windows ⚡ nuclei
9.3
CRITICAL
EPSS
83.0%
2022 1 PoC

Local File Inclusion vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

CVE-2022-27660
LinkHub Mesh Wifi General
9.3
CRITICAL
EPSS
0.5%
2022 CWE-284 1 PoC

A denial of service vulnerability exists in the confctl_set_guest_wlan functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to denial of service. An attacker can send packets to trigger this vulnerability.

CVE-2022-50919
Tdarr General
9.3
CRITICAL
EPSS
1.5%
2022 CWE-78 1 PoC

Tdarr 2.00.15 contains an unauthenticated remote code execution vulnerability in its Help terminal that allows attackers to inject and chain arbitrary commands. Attackers can exploit the lack of input filtering by chaining commands like `--help; curl .py | python` to execute remote code without authentication.

CVE-2022-50796
Impact/Pulse/First General
9.3
CRITICAL
EPSS
1.1%
2022 CWE-22 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.