4741 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2018-3897
SmartThings Hub STH-ETH-250 Web
9.9
CRITICAL
EPSS
0.4%
2018 1 PoC

An exploitable buffer overflow vulnerabilities exist in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub with Firmware version 0.20.17. The video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "callbackUrl" value in order to exploit this vulnerability.

CVE-2018-3856
Samsung Web
9.9
CRITICAL
EPSS
4.8%
2018 1 PoC

An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The device incorrectly handles spaces in the URL field, leading to an arbitrary operating system command injection. An attacker can send a series of HTTP requests to trigger this vulnerability.

CVE-2018-3876
SmartThings Hub STH-ETH-250 Web
9.9
CRITICAL
EPSS
0.4%
2018 1 PoC

An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit this vulnerability.

CVE-2018-3895
Samsung Web
9.9
CRITICAL
EPSS
0.4%
2018 1 PoC

An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250 Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long 'endTime' value in order to exploit this vulnerability. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2018-3863
SmartThings Hub STH-ETH-250 Web
9.9
CRITICAL
EPSS
0.4%
2018 1 PoC

On Samsung SmartThings Hub STH-ETH-250 devices with firmware version 0.20.17, the video-core process incorrectly extracts fields from a user-controlled JSON payload, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability. A strcpy overflows the destination buffer, which has a size of 40 bytes. An attacker can send an arbitrarily long "user" value in order to exploit this vulnerability.

CVE-2022-30534
AVideo Web
9.9
CRITICAL
EPSS
12.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-26780
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.9%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-2550
hestiacp/hestiacp General
9.9
CRITICAL
EPSS
8.8%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

CVE-2022-26510
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.5%
2022 CWE-347 1 PoC

A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-24665
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
2.1%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

CVE-2022-29517
lansweeper Web
9.9
CRITICAL
EPSS
46.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-21276
Communications Billing and Revenue Management Web Database
9.9
CRITICAL
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communicat

CVE-2022-37425
Software Genérico General
9.9
CRITICAL
EPSS
2.1%
2022 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

CVE-2022-26420
InRouter302 Networking
9.9
CRITICAL
EPSS
9.1%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-1770
polonel/trudesk General
9.9
CRITICAL
EPSS
0.3%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-30547
AVideo Web
9.9
CRITICAL
EPSS
20.7%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-46642
Software Genérico General
9.9
CRITICAL
EPSS
6.9%
2022 1 PoC

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.

CVE-2022-36786
DSL-224 Web Networking
9.9
CRITICAL
EPSS
0.4%
2022 1 PoC

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

CVE-2022-0415
gogs/gogs General ⚡ nuclei
9.9
CRITICAL
EPSS
89.6%
2022 CWE-20 1 PoC

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

CVE-2022-26085
InRouter302 Web Networking
9.9
CRITICAL
EPSS
2.7%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.