94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4118
Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop Web Database Windows
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users

CVE-2022-48113
Software Genérico General
9.8
CRITICAL
EPSS
1.8%
2022 1 PoC

A vulnerability in TOTOLINK N200RE_v5 firmware V9.3.5u.6139 allows unauthenticated attackers to access the telnet service via a crafted POST request. Attackers are also able to leverage this vulnerability to login as root via hardcoded credentials.

CVE-2022-4117
IWS Web Database Windows ⚡ nuclei
9.8
CRITICAL
EPSS
62.9%
2022 1 PoC

The IWS WordPress plugin through 1.0 does not properly escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to an unauthenticated SQL injection.

CVE-2022-4693
User Verification Web Windows
9.8
CRITICAL
EPSS
10.2%
2022 1 PoC

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.

CVE-2022-26134
🔥 KEV Confluence Data Center General ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 84 PoCs

In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The affected versions are from 1.3.0 before 7.4.17, from 7.13.0 before 7.13.7, from 7.14.0 before 7.14.3, from 7.15.0 before 7.15.2, from 7.16.0 before 7.16.4, from 7.17.0 before 7.17.4, and from 7.18.0 before 7.18.1.

CVE-2022-47939
Software Genérico Windows
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.

CVE-2022-44930
Software Genérico General
9.8
CRITICAL
EPSS
28.1%
2022 1 PoC

D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.

CVE-2022-47118
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

CVE-2022-41794
OpenImageIO General
9.8
CRITICAL
EPSS
0.9%
2022 CWE-122 1 PoC

A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-44183
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 2 PoCs

Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via function formSetWifiGuestBasic.

CVE-2022-38573
Software Genérico General
9.8
CRITICAL
EPSS
0.8%
2022 2 PoCs

10-Strike Network Inventory Explorer v9.3 was discovered to contain a buffer overflow via the Add Computers function.

CVE-2022-31860
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 3 PoCs

An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.

CVE-2022-43002
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the wizardstep54_pskpwd parameter at /goform/form2WizardStep54.

CVE-2022-35508
Software Genérico Web
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Proxmox Virtual Environment (PVE) and Proxmox Mail Gateway (PMG) are vulnerable to SSRF when proxying HTTP requests between pve(pmg)proxy and pve(pmg)daemon. An attacker with an unprivileged account can craft an HTTP request to achieve SSRF and file disclosure of any files on the server. Also, in Proxmox Mail Gateway, privilege escalation to the root@pam account is possible if the backup feature has ever been used, because backup files such as pmg-backup_YYYY_MM_DD_*.tgz have 0644 permissions and contain an authkey value. This is fixed in pve-http-server 4.1-3.

CVE-2022-24990
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 9 PoCs

TerraMaster NAS 4.2.29 and earlier allows remote attackers to discover the administrative password by sending "User-Agent: TNAS" to module/api.php?mobile/webNasIPS and then reading the PWD field in the response.

CVE-2022-36320
Firefox General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.

CVE-2022-34268
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. /clientLogin deserializes Java objects without authentication, leading to command execution on the host.

CVE-2022-40943
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.6%
2022 1 PoC

Dairy Farm Shop Management System 1.0 is vulnerable to SQL Injection via bwdate-report-ds.php file.

CVE-2022-0558
microweber/microweber Web
9.8
CRITICAL
EPSS
0.3%
2022 CWE-79 2 PoCs

Cross-site Scripting (XSS) - Stored in Packagist microweber/microweber prior to 1.2.11.