550 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2022-47003
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
24.4%
2022 0 PoCs

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

CVE-2022-31706
vRealize Log Insight (vRLI) General ⚡ nuclei
9.8
CRITICAL
EPSS
90.2%
2022 1 PoC

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

CVE-2022-3980
Sophos Mobile managed on-premises General ⚡ nuclei
9.8
CRITICAL
EPSS
88.0%
2022 0 PoCs

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

CVE-2022-26143
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.1%
2022 2 PoCs

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.

CVE-2022-25369
Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
80.1%
2022 0 PoCs

An issue was discovered in Dynamicweb before 9.12.8. An attacker can add a new administrator user without authentication. This flaw exists due to a logic issue when determining if the setup phases of the product can be run again. Once an attacker is authenticated as the new admin user they have added, it is possible to upload an executable file and achieve command execution. This is fixed in 9.5.9, 9.6.16, 9.7.8, 9.8.11, 9.9.8, 9.10.18, 9.12.8, and 9.13.0 (and later).

CVE-2022-1768
RSVPMaker Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
86.1%
2022 CWE-89 1 PoC

The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to insufficient escaping and parameterization on user supplied data passed to multiple SQL queries in the ~/rsvpmaker-email.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to, and including, 9.3.2. Please note that this is separate from CVE-2022-1453 & CVE-2022-1505.

CVE-2022-4447
Fontsy Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
77.9%
2022 1 PoC

The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-37042
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 4 PoCs

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CVE-2022-22954
🔥 KEV VMware Workspace ONE Access and Identity Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 36 PoCs

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVE-2022-0342
USG/ZyWALL series firmware Networking ⚡ nuclei
9.8
CRITICAL
EPSS
92.4%
2022 CWE-287 0 PoCs

An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.

CVE-2022-1388
🔥 KEV BIG-IP Networking ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-306 87 PoCs

On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVE-2022-46071
Software Genérico DevOps Database ⚡ nuclei
9.8
CRITICAL
EPSS
79.2%
2022 2 PoCs

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

CVE-2022-26352
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 2 PoCs

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

CVE-2022-22965
🔥 KEV Spring Framework Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 CWE-94 79 PoCs

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVE-2022-4117
IWS Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2022 1 PoC

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

CVE-2022-22536
🔥 KEV SAP NetWeaver and ABAP Platform General ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2022 CWE-444 6 PoCs

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server 7.53 and SAP Web Dispatcher are vulnerable for request smuggling and request concatenation. An unauthenticated attacker can prepend a victim's request with arbitrary data. This way, the attacker can execute functions impersonating the victim or poison intermediary Web caches. A successful attack could result in complete compromise of Confidentiality, Integrity and Availability of the system.

CVE-2022-3481
WooCommerce Dropshipping Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
48.0%
2022 1 PoC

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

CVE-2022-40624
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
84.7%
2022 1 PoC

pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.

CVE-2022-4305
Login as User or Customer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
83.1%
2022 1 PoC

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.