94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2651
bookwyrm-social/bookwyrm General
9.8
CRITICAL
EPSS
16.9%
2022 CWE-305 1 PoC

Authentication Bypass by Primary Weakness in GitHub repository bookwyrm-social/bookwyrm prior to 0.4.5.

CVE-2022-39428
Web Applications Desktop Integrator Web Database
9.8
CRITICAL
EPSS
22.2%
2022 1 PoC

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-4383
CBX Petition for WordPress Web Database Windows
9.8
CRITICAL
EPSS
2.6%
2022 1 PoC

The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-3477
tagDiv Composer Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
63.5%
2022 CWE-287 1 PoC

The tagDiv Composer WordPress plugin before 3.5, required by the Newspaper WordPress theme before 12.1 and Newsmag WordPress theme before 5.2.2, does not properly implement the Facebook login feature, allowing unauthenticated attackers to login as any user by just knowing their email address

CVE-2022-36436
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2022 1 PoC

OSU Open Source Lab VNCAuthProxy through 1.1.1 is affected by an vncap/vnc/protocol.py VNCServerAuthenticator authentication-bypass vulnerability that could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC session. A remote attacker with network access to the proxy server could leverage this vulnerability to connect to VNC servers protected by the proxy server without providing any authentication credentials. Exploitation of this issue requires that the proxy server is currently accepting connections for the target VNC server.

CVE-2022-23852
Software Genérico General
9.8
CRITICAL
EPSS
1.7%
2022 2 PoCs

Expat (aka libexpat) before 2.4.4 has a signed integer overflow in XML_GetBuffer, for configurations with a nonzero XML_CONTEXT_BYTES.

CVE-2022-26133
Bitbucket Data Center General
9.8
CRITICAL
EPSS
81.4%
2022 4 PoCs

SharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6, 7.18.0 and later prior to 7.18.4, 7.19.0 and later prior to 7.19.4, and 7.20.0 allow a remote, unauthenticated attacker to execute arbitrary code via Java deserialization.

CVE-2022-47027
Software Genérico General
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Timmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionary traversal vulnerability and achieve arbitrary code execution.

CVE-2022-37042
🔥 KEV Software Genérico General ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 4 PoCs

Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. By bypassing authentication (i.e., not having an authtoken), an attacker can upload arbitrary files to the system, leading to directory traversal and remote code execution. NOTE: this issue exists because of an incomplete fix for CVE-2022-27925.

CVE-2022-43265
Software Genérico Web
9.8
CRITICAL
EPSS
0.8%
2022 2 PoCs

An arbitrary file upload vulnerability in the component /pages/save_user.php of Canteen Management System v1.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-25893
vm2 General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.

CVE-2022-47865
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.

CVE-2022-47861
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.

CVE-2022-22963
🔥 KEV Spring Cloud Function Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-94 32 PoCs

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CVE-2022-45551
Software Genérico Networking
9.8
CRITICAL
EPSS
3.1%
2022 1 PoC

An issue discovered in Shenzhen Zhiboton Electronics ZBT WE1626 Router v 21.06.18 allows attackers to escalate privileges via WGET command to the Network Diagnosis endpoint.

CVE-2022-31890
Software Genérico Web Database
9.8
CRITICAL
EPSS
13.8%
2022 1 PoC

SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit a7842d494889fd5533d13deb3c6a7789768795ae via the order parameter to the getOrder function.

CVE-2022-47866
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.

CVE-2022-44877
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 14 PoCs

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.

CVE-2022-25236
Software Genérico General
9.8
CRITICAL
EPSS
7.4%
2022 3 PoCs

xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator characters into namespace URIs.

CVE-2022-42998
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the srcip parameter at /goform/form2IPQoSTcAdd.