94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-44136
Software Genérico Web
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

CVE-2022-47986
🔥 KEV Aspera Faspex Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 CWE-502 4 PoCs

IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a specially crafted obsolete API call, an attacker could exploit this vulnerability to execute arbitrary code on the system. The obsolete API call was removed in Faspex 4.4.2 PL2. IBM X-Force ID: 243512.

CVE-2022-0748
post-loader Web
9.8
CRITICAL
EPSS
1.2%
2022 1 PoC

The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.

CVE-2022-44291
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
66.4%
2022 0 PoCs

webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php.

CVE-2022-40916
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2022 2 PoCs

Tiny File Manager v2.4.7 and below is vulnerable to session fixation.

CVE-2022-48253
Software Genérico Web
9.8
CRITICAL
EPSS
33.5%
2022 1 PoC

nhttpd in Nostromo before 2.1 is vulnerable to a path traversal that may allow an attacker to execute arbitrary commands on the remote server. The vulnerability occurs when the homedirs option is used.

CVE-2022-20473
Android General
9.8
CRITICAL
EPSS
50.9%
2022 1 PoC

In toLanguageTag of LocaleListCache.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239267173

CVE-2022-44832
Software Genérico General
9.8
CRITICAL
EPSS
23.2%
2022 1 PoC

D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.

CVE-2022-21186
@acrontum/filesystem-template Web
9.8
CRITICAL
EPSS
6.6%
2022 1 PoC

The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.

CVE-2022-41352
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.1%
2022 8 PoCs

An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. An attacker can upload arbitrary files through amavis via a cpio loophole (extraction to /opt/zimbra/jetty/webapps/zimbra/public) that can lead to incorrect access to any other user accounts. Zimbra recommends pax over cpio. Also, pax is in the prerequisites of Zimbra on Ubuntu; however, pax is no longer part of a default Red Hat installation after RHEL 6 (or CentOS 6). Once pax is installed, amavis automatically prefers it over cpio.

CVE-2022-4395
Membership For WooCommerce Web Windows
9.8
CRITICAL
EPSS
76.3%
2022 3 PoCs

The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as malicious PHP code, and achieve RCE.

CVE-2022-40021
Software Genérico General
9.8
CRITICAL
EPSS
3.3%
2022 1 PoC

QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.

CVE-2022-45481
Lazy Mouse General
9.8
CRITICAL
EPSS
2.6%
2022 CWE-306 1 PoC

The default configuration of Lazy Mouse does not require a password, allowing remote unauthenticated users to execute arbitrary code with no prior authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-44202
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR878 1.02B04 and 1.02B05 are vulnerable to Buffer Overflow.

CVE-2022-2068
OpenSSL General
9.8
CRITICAL
EPSS
18.6%
2022 1 PoC

In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehash script does not properly sanitise shell metacharacters to prevent command injection were found by code review. When the CVE-2022-1292 was fixed it was not discovered that there are other places in the script where the file names of certificates being hashed were possibly passed to a command executed through the shell. This script is distributed by some operating systems in a manner where it is automatically executed. On such operating systems, an attacker could execute arbi

CVE-2022-44250
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.

CVE-2022-35866
Backup and Recovery Database
9.8
CRITICAL
EPSS
0.4%
2022 CWE-798 1 PoC

This vulnerability allows remote attackers to bypass authentication on affected installations of Vinchin Backup and Recovery 6.5.0.17561. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of the MySQL server. The server uses a hard-coded password for the administrator user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17139.

CVE-2022-36784
Elsight Halo Web
9.8
CRITICAL
EPSS
1.9%
2022 1 PoC

Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.

CVE-2022-24706
🔥 KEV Apache CouchDB Web Networking
9.8
CRITICAL
EPSS
94.4%
2022 CWE-1188 9 PoCs

In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.

CVE-2022-26143
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
89.1%
2022 2 PoCs

The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.