94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-47769
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2022 1 PoC

An arbitrary file write vulnerability in Serenissima Informatica Fast Checkin v1.0 allows unauthenticated attackers to upload malicious files in the web root of the application to gain access to the server via the web shell.

CVE-2022-27518
🔥 KEV Citrix Gateway, Citrix ADC Networking
9.8
CRITICAL
EPSS
27.7%
2022 CWE-664 1 PoC

Unauthenticated remote arbitrary code execution

CVE-2022-44262
Software Genérico General
9.8
CRITICAL
EPSS
1.2%
2022 2 PoCs

ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

CVE-2022-4851
usememos/memos General
9.8
CRITICAL
EPSS
0.4%
2022 CWE-229 1 PoC

Improper Handling of Values in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-39185
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.

CVE-2022-3921
Listingo Web Windows
9.8
CRITICAL
EPSS
7.8%
2022 1 PoC

The Listingo WordPress theme before 3.2.7 does not validate files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files and lead to RCE

CVE-2022-3574
WPForms Pro Web Windows
9.8
CRITICAL
EPSS
1.3%
2022 CWE-1236 1 PoC

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

CVE-2022-44204
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

CVE-2022-31056
glpi Database
9.8
CRITICAL
EPSS
5.2%
2022 CWE-89 1 PoC

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.

CVE-2022-46581
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.

CVE-2022-46640
Software Genérico Web
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

CVE-2022-3634
Contact Form 7 Database Addon Web Windows
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

CVE-2022-40434
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.

CVE-2022-45710
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

CVE-2022-40797
Software Genérico Web
9.8
CRITICAL
EPSS
12.6%
2022 1 PoC

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

CVE-2022-4047
Return Refund and Exchange For WooCommerce Web Windows
9.8
CRITICAL
EPSS
73.3%
2022 2 PoCs

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVE-2022-44003
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

CVE-2022-45712
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.

CVE-2022-3915
Dokan Web Database Windows
9.8
CRITICAL
EPSS
3.2%
2022 1 PoC

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users