7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46372
AR7088H-A General
7.2
HIGH
EPSS
0.5%
2022 1 PoC

Alotcer - AR7088H-A firmware version 16.10.3 Command execution Improper validation of unspecified input field may allow Authenticated command execution.

CVE-2022-24899
contao Web ⚡ nuclei
7.2
HIGH
EPSS
44.0%
2022 CWE-79 0 PoCs

Contao is a powerful open source CMS that allows you to create professional websites and scalable web applications. In versions of Contao prior to 4.13.3 it is possible to inject code into the canonical tag. As a workaround users may disable canonical tags in the root page settings.

CVE-2022-3249
WP CSV Exporter Web Database Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly sanitise and escape some parameters before using them in a SQL statement, allowing high privilege users such as admin to perform SQL injection attacks

CVE-2022-42845
macOS General
7.2
HIGH
EPSS
1.5%
2022 6 PoCs

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app with root privileges may be able to execute arbitrary code with kernel privileges.

CVE-2022-3425
Analyticator Web Windows
7.2
HIGH
EPSS
0.8%
2022 1 PoC

The Analyticator WordPress plugin before 6.5.6 unserializes user input provided via the settings, which could allow high-privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.

CVE-2022-1219
pimcore/pimcore Web Database
7.2
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

SQL injection in RecyclebinController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

CVE-2022-38715
QUARTZ-GOLD Web
7.2
HIGH
EPSS
7.5%
2022 CWE-489 2 PoCs

A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-24376
git-promise Web
7.2
HIGH
EPSS
2.5%
2022 2 PoCs

All versions of package git-promise are vulnerable to Command Injection due to an inappropriate fix of a prior [vulnerability](https://security.snyk.io/vuln/SNYK-JS-GITPROMISE-567476) in this package. **Note:** Please note that the vulnerability will not be fixed. The README file was updated with a warning regarding this issue.

CVE-2022-43146
Software Genérico Web
7.2
HIGH
EPSS
0.9%
2022 2 PoCs

An arbitrary file upload vulnerability in the image upload function of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-36429
Orbi Satellite RBS750 General
7.2
HIGH
EPSS
0.5%
2022 CWE-912 2 PoCs

A command execution vulnerability exists in the ubus backend communications functionality of Netgear Orbi Satellite RBS750 4.6.8.5. A specially-crafted JSON object can lead to arbitrary command execution. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVE-2022-46566
Software Genérico Networking
7.2
HIGH
EPSS
2.0%
2022 5 PoCs

D-Link DIR-882 DIR882A1_FW130B06, DIR-878 DIR_878_FW1.30B08 was discovered to contain a stack overflow via the Password parameter in the SetQuickVPNSettings module.

CVE-2022-4546
Mapwiz Web Database Windows
7.2
HIGH
EPSS
0.5%
2022 1 PoC

The Mapwiz WordPress plugin through 1.0.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

CVE-2022-4355
LetsRecover Web Database Windows
7.2
HIGH
EPSS
0.6%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin

CVE-2022-40985
QUARTZ-GOLD General
7.2
HIGH
EPSS
1.7%
2022 CWE-120 2 PoCs

Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer overflow is in the function that manages the '(ddns1|ddns2) hostname WORD' command template.

CVE-2022-0921
microweber/microweber General
7.2
HIGH
EPSS
4.6%
2022 CWE-94 1 PoC

Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-3418
Import any XML or CSV File to WordPress Web Windows
7.2
HIGH
EPSS
1.4%
2022 CWE-94 1 PoC

The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbitrary files

CVE-2022-3335
Kadence WooCommerce Email Designer Web Windows
7.2
HIGH
EPSS
0.9%
2022 CWE-502 1 PoC

The Kadence WooCommerce Email Designer WordPress plugin before 1.5.7 unserialises the content of an imported file, which could lead to PHP object injections issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-1681
requarks/wiki General
7.2
HIGH
EPSS
0.3%
2022 CWE-288 1 PoC

Authentication Bypass Using an Alternate Path or Channel in GitHub repository requarks/wiki prior to 2.5.281. User can get root user permissions

CVE-2022-3490
Checkout Field Editor (Checkout Manager) for WooCommerce Web Windows
7.2
HIGH
EPSS
0.9%
2022 1 PoC

The Checkout Field Editor (Checkout Manager) for WooCommerce WordPress plugin before 1.8.0 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present