94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4120
Stop Spammers Security | Block Spam Users, Comments, Forms Web Windows
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

The Stop Spammers Security | Block Spam Users, Comments, Forms WordPress plugin before 2022.6 passes base64 encoded user input to the unserialize() PHP function when CAPTCHA are used as second challenge, which could lead to PHP Object injection if a plugin installed on the blog has a suitable gadget chain

CVE-2022-4328
WooCommerce Checkout Field Manager Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
80.3%
2022 1 PoC

The WooCommerce Checkout Field Manager WordPress plugin before 18.0 does not validate files to be uploaded, which could allow unauthenticated attackers to upload arbitrary files such as PHP on the server

CVE-2022-37235
Software Genérico Networking
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncat

CVE-2022-44004
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insecure design or lack of authentication, unauthenticated attackers can complete the password-reset process for any account and set a new password.

CVE-2022-48107
Software Genérico General
9.8
CRITICAL
EPSS
21.9%
2022 1 PoC

D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the component /setnetworksettings/IPAddress. This vulnerability allows attackers to escalate privileges to root via a crafted payload.

CVE-2022-45172
Software Genérico Web Cloud
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

An issue was discovered in LIVEBOX Collaboration vDesk before v018. Broken Access Control can occur under the /api/v1/registration/validateEmail endpoint, the /api/v1/vdeskintegration/user/adduser endpoint, and the /api/v1/registration/changePasswordUser endpoint. The web application is affected by flaws in authorization logic, through which a malicious user (with no privileges) is able to perform privilege escalation to the administrator role, and steal the accounts of any users on the system.

CVE-2022-44201
Software Genérico General
9.8
CRITICAL
EPSS
2.1%
2022 1 PoC

D-Link DIR823G 1.02B05 is vulnerable to Commad Injection.

CVE-2022-47859
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.

CVE-2022-4357
LetsRecover Web Database Windows
9.8
CRITICAL
EPSS
2.1%
2022 2 PoCs

The LetsRecover WordPress plugin before 1.2.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-44283
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

AVS Audio Converter 10.3 is vulnerable to Buffer Overflow.

CVE-2022-31706
vRealize Log Insight (vRLI) General ⚡ nuclei
9.8
CRITICAL
EPSS
90.2%
2022 1 PoC

The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.

CVE-2022-46583
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the reboot_type parameter in the wizard_ipv6 (sub_41C380) function.

CVE-2022-22954
🔥 KEV VMware Workspace ONE Access and Identity Manager General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 36 PoCs

VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code execution.

CVE-2022-4445
FL3R FeelBox Web Database Windows
9.8
CRITICAL
EPSS
4.7%
2022 1 PoC

The FL3R FeelBox WordPress plugin through 8.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.

CVE-2022-45047
Apache MINA SSHD Web Networking
9.8
CRITICAL
EPSS
5.7%
2022 CWE-502 1 PoC

Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD can choose for loading the host keys of an SSH server.

CVE-2022-35244
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
0.7%
2022 CWE-134 1 PoC

A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this vulnerability.

CVE-2022-41837
OpenImageIO General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-562 1 PoC

An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-44938
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.

CVE-2022-46366
Apache Tapestry Web
9.8
CRITICAL
EPSS
3.9%
2022 CWE-502 2 PoCs

Apache Tapestry 3.x allows deserialization of untrusted data, leading to remote code execution. This issue is similar to but distinct from CVE-2020-17531, which applies the the (also unsupported) 4.x version line. NOTE: This vulnerability only affects Apache Tapestry version line 3.x, which is no longer supported by the maintainer. Users are recommended to upgrade to a supported version line of Apache Tapestry.

CVE-2022-27805
iota All-In-One Security Kit General
9.8
CRITICAL
EPSS
1.3%
2022 CWE-284 1 PoC

An authentication bypass vulnerability exists in the GHOME control functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted network request can lead to arbitrary XCMD execution. An attacker can send a malicious XML payload to trigger this vulnerability.