7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-25148
WP Statistics Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
57.8%
2022 CWE-89 1 PoC

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_id parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CVE-2022-41991
QUARTZ-GOLD General
9.8
CRITICAL
EPSS
0.5%
2022 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to a heap buffer overflow. An attacker can send a network request to trigger this vulnerability.

CVE-2022-45708
Software Genérico Web
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDelPortMapping function.

CVE-2022-44928
Software Genérico General
9.8
CRITICAL
EPSS
15.2%
2022 1 PoC

D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.

CVE-2022-44290
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
66.4%
2022 0 PoCs

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php.

CVE-2022-40296
PHP Point of Sale Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-918 1 PoC

The application was vulnerable to a Server-Side Request Forgery attacks, allowing the backend server to interact with unexpected endpoints, potentially including internal and local services, leading to attacks in other downstream systems.

CVE-2022-38922
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

BluePage CMS thru 3.9 processes an insufficiently sanitized HTTP Header Cookie value allowing MySQL Injection in the 'users-cookie-settings' token using a Time-based blind SLEEP payload.

CVE-2022-41138
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.

CVE-2022-4305
Login as User or Customer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
83.1%
2022 1 PoC

The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure that users are allowed to log in as another one, which could allow unauthenticated attackers to obtain a valid admin session.

CVE-2022-43138
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

CVE-2022-44801
Software Genérico General
9.8
CRITICAL
EPSS
1.1%
2022 1 PoC

D-Link DIR-878 1.02B05 is vulnerable to Incorrect Access Control.

CVE-2022-21306
WebLogic Server Database
9.8
CRITICAL
EPSS
36.9%
2022 2 PoCs

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-47873
Software Genérico General
9.8
CRITICAL
EPSS
0.3%
2022 2 PoCs

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

CVE-2022-46585
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the REMOTE_USER parameter in the get_access (sub_45AC2C) function.

CVE-2022-47767
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super administration privileges to the attacker. This affects Solar-Log devices that use firmware version v4.2.7 up to v5.1.1 (included). This does not exist in SL 200, 500, 1000 / fixed in 4.2.8 for SL 250, 300, 1200, 2000, SL 50 Gateway / fixed in 5.1.2 / 6.0.0 for SL Base.

CVE-2022-45709
Software Genérico General
9.8
CRITICAL
EPSS
5.3%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

CVE-2022-44188
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.0.8 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter enable_band_steering.

CVE-2022-2595
kromitgmbh/titra General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.