94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-43325
Software Genérico General
9.8
CRITICAL
EPSS
30.0%
2022 1 PoC

An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.

CVE-2022-47945
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
90.3%
2022 0 PoCs

ThinkPHP Framework before 6.0.14 allows local file inclusion via the lang parameter when the language pack feature is enabled (lang_switch_on=true). An unauthenticated and remote attacker can exploit this to execute arbitrary operating system commands, as demonstrated by including pearcmd.php.

CVE-2022-25644
@pendo324/get-process-by-name General
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

All versions of package @pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution due to improper sanitization of getProcessByName function.

CVE-2022-45460
Software Genérico Web
9.8
CRITICAL
EPSS
55.3%
2022 1 PoC

Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow an unauthenticated and remote user to exploit a stack-based buffer overflow and crash the web server, resulting in a system reboot. An unauthenticated and remote attacker can execute arbitrary code by sending a crafted HTTP request that triggers the overflow condition via a long URI passed to a sprintf call. NOTE: this is different than CVE-2018-10088, but this may overlap CVE-2017-16725.

CVE-2022-39952
FortiNAC Web Networking ⚡ nuclei
9.8
CRITICAL
EPSS
93.8%
2022 CWE-73 4 PoCs

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

CVE-2022-2037
tooljet/tooljet General
9.8
CRITICAL
EPSS
0.3%
2022 CWE-1125 1 PoC

Excessive Attack Surface in GitHub repository tooljet/tooljet prior to v1.16.0.

CVE-2022-29851
Software Genérico General
9.8
CRITICAL
EPSS
1.6%
2022 1 PoC

documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Injection because file conversion may occur for an EPS document that is disguised as a PDF document.

CVE-2022-47966
🔥 KEV Software Genérico Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 11 PoCs

Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections, and the ManageEngine applications did not provide those protections. This affects Access Manager Plus before 4308, Active Directory 360 before 4310, ADAudit Plus before 7081, ADManager Plus before 7162, ADSelfService Plus before 6211, Analytics Plus before 5150, Application Control

CVE-2022-37056
Software Genérico General
9.8
CRITICAL
EPSS
20.2%
2022 CWE-78 2 PoCs

D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command Injection via /cgibin, hnap_main,

CVE-2022-32224
https://github.com/rails/rails Web Database
9.8
CRITICAL
EPSS
1.9%
2022 CWE-502 1 PoC

A possible escalation to RCE vulnerability exists when using YAML serialized columns in Active Record < 7.0.3.1, <6.1.6.1, <6.0.5.1 and <5.2.8.1 which could allow an attacker, that can manipulate data in the database (via means like SQL injection), the ability to escalate to an RCE.

CVE-2022-26258
🔥 KEV Software Genérico Web
9.8
CRITICAL
EPSS
87.2%
2022 2 PoCs

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

CVE-2022-24627
Software Genérico Web Database ⚡ nuclei
9.8
CRITICAL
EPSS
48.7%
2022 0 PoCs

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

CVE-2022-44252
Software Genérico General
9.8
CRITICAL
EPSS
14.9%
2022 1 PoC

TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.

CVE-2022-32588
ImageGear General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the PICT parsing pctwread_14841 functionality of Accusoft ImageGear 20.0. A specially-crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-26318
🔥 KEV Software Genérico General
9.8
CRITICAL
EPSS
92.2%
2022 5 PoCs

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

CVE-2022-46887
Software Genérico Web Database
9.8
CRITICAL
EPSS
2.8%
2022 1 PoC

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.

CVE-1999-1588
Software Genérico General
9.8
CRITICAL
EPSS
18.2%
1999 1 PoC

Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.

CVE-2006-5678
Software Genérico Web
9.8
CRITICAL
EPSS
1.5%
2006 1 PoC

PHP remote file inclusion vulnerability in common/visiteurs/include/library.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_modules_dir parameter. NOTE: CVE disputes this vulnerability, because the inclusion occurs in a function that is not called during a direct request to library.inc.php

CVE-2006-6863
Software Genérico Web Windows
9.8
CRITICAL
EPSS
5.6%
2006 1 PoC

PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote attackers to execute arbitrary PHP code via a URL in the boarddir parameter. NOTE: CVE disputes this issue, since $boarddir is set to a fixed value

CVE-2025-61548
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2025 1 PoC

SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro WebDesk version 18.34 (fixed in 19.69). Unsanitized user input is incorporated directly into SQL queries without proper parameterization or escaping. This vulnerability allows remote attackers to execute arbitrary SQL commands