94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0316
WeStand Web Windows
9.8
CRITICAL
EPSS
38.9%
2022 2 PoCs

The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme, statfort WordPress theme, club-theme WordPress theme, kingclub-theme WordPress theme, spikes WordPress theme, spikes-black WordPress theme, soundblast WordPress theme, bolster WordPress theme from ChimpStudio and PixFill does not have any authorisation and upload validation in the lang_upload.php file, allowing any unauthenticated attacker to upload arbitrary files to the web server.

CVE-2022-39989
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

An issue was discovered in Fighting Cock Information System 1.0, which uses default credentials, but does not force nor prompt the administrators to change the credentials.

CVE-2022-44804
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

D-Link DIR-882 1.10B02 and1.20B06 is vulnerable to Buffer Overflow via the websRedirect function.

CVE-2022-47123
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey3 parameter at /goform/WifiBasicSet.

CVE-2022-4797
usememos/memos General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-37454
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

The Keccak XKCP SHA-3 reference implementation before fdc6fef has an integer overflow and resultant buffer overflow that allows attackers to execute arbitrary code or eliminate expected cryptographic properties. This occurs in the sponge function interface.

CVE-2022-3982
Booking calendar, Appointment Booking System Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
74.2%
2022 1 PoC

The Booking calendar, Appointment Booking System WordPress plugin before 3.2.2 does not validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE

CVE-2022-46586
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the qcawifi.wifi%d_vap%d.maclist parameter in the kick_ban_wifi_mac_allow (sub_415B00) function.

CVE-2022-44808
Software Genérico Web
9.8
CRITICAL
EPSS
19.8%
2022 1 PoC

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to execute arbitrary operating system commands through well-designed /HNAP1 requests. Before the HNAP API function can process the request, the system function executes an untrusted command that triggers the vulnerability.

CVE-2022-3481
WooCommerce Dropshipping Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
48.0%
2022 1 PoC

The WooCommerce Dropshipping WordPress plugin before 4.4 does not properly sanitise and escape a parameter before using it in a SQL statement via a REST endpoint available to unauthenticated users, leading to a SQL injection

CVE-2022-30004
Software Genérico Database
9.8
CRITICAL
EPSS
0.8%
2022 2 PoCs

Sourcecodester Online Market Place Site v1.0 suffers from an unauthenticated blind SQL Injection Vulnerability allowing remote attackers to dump the SQL database via time-based SQL injection..

CVE-2022-44929
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

An access control issue in D-Link DVG-G5402SP GE_1.03 allows unauthenticated attackers to escalate privileges via arbitrarily editing VoIP SIB profiles.

CVE-2022-23219
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.

CVE-2022-48108
Software Genérico General
9.8
CRITICAL
EPSS
21.9%
2022 1 PoC

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /SetNetworkSettings/SubnetMask. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-45896
Software Genérico General
9.8
CRITICAL
EPSS
3.0%
2022 1 PoC

Planet eStream before 6.72.10.07 allows unauthenticated upload of arbitrary files: Choose a Video / Related Media or Upload Document. Upload2.ashx can be used, or Ajax.asmx/ProcessUpload2. This leads to remote code execution.

CVE-2022-40918
Software Genérico Web
9.8
CRITICAL
EPSS
4.3%
2022 3 PoCs

Buffer overflow in firmware lewei_cam binary version 2.0.10 in Force 1 Discovery Wifi U818A HD+ FPV Drone allows attacker to gain remote code execution as root user via a specially crafted UDP packet. Please update the Reference section to these links > http://thiscomputer.com/ > https://www.bostoncyber.org/ > https://medium.com/@meekworth/exploiting-the-lw9621-drone-camera-module-773f00081368

CVE-2022-45479
PC Keyboard WiFi & Bluetooth General
9.8
CRITICAL
EPSS
3.6%
2022 CWE-306 1 PoC

PC Keyboard allows remote unauthenticated users to send instructions to the server to execute arbitrary code without any previous authorization or authentication. CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-24491
Windows 10 Version 1809 Windows
9.8
CRITICAL
EPSS
37.6%
2022 1 PoC

Windows Network File System Remote Code Execution Vulnerability

CVE-2022-44186
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow in /usr/sbin/httpd via parameter wan_dns1_pri.