7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2166
mastodon/mastodon General
9.8
CRITICAL
EPSS
1.4%
2022 CWE-307 1 PoC

Improper Restriction of Excessive Authentication Attempts in GitHub repository mastodon/mastodon prior to 4.0.0.

CVE-2022-44451
Open Babel General
9.8
CRITICAL
EPSS
0.2%
2022 CWE-824 1 PoC

A use of uninitialized pointer vulnerability exists in the MSI format atom functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-47861
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.

CVE-2022-2932
bustle/mobiledoc-kit Web
9.8
CRITICAL
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository bustle/mobiledoc-kit prior to 0.14.2.

CVE-2022-26352
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.3%
2022 2 PoCs

An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form request to post a file whose filename is not initially sanitized. This allows directory traversal, in which the file is saved outside of the intended storage location. If anonymous content creation is enabled, this allows an unauthenticated attacker to upload an executable file, such as a .jsp file, that can lead to remote code execution.

CVE-2022-46071
Software Genérico DevOps Database ⚡ nuclei
9.8
CRITICAL
EPSS
79.2%
2022 2 PoCs

There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access.

CVE-2022-43999
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to exposed CORBA management services, arbitrary system commands can be executed on the server.

CVE-2022-39184
BV-10 Performance Endpoint Unit General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.

CVE-2022-22963
🔥 KEV Spring Cloud Function Web Cloud ⚡ nuclei
9.8
CRITICAL
EPSS
94.5%
2022 CWE-94 32 PoCs

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

CVE-2022-1609
school-management-pro Web Windows ⚡ nuclei
9.8
CRITICAL
EPSS
93.5%
2022 10 PoCs

The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.

CVE-2022-40876
Software Genérico Web
9.8
CRITICAL
EPSS
4.5%
2022 2 PoCs

In Tenda ax1803 v1.0.0.1, the http requests handled by the fromAdvSetMacMtuWan functions, wanSpeed, cloneType, mac, can cause a stack overflow and enable remote code execution (RCE).

CVE-2022-36934
WhatsApp for iOS General
9.8
CRITICAL
EPSS
12.7%
2022 CWE-122 1 PoC

An integer overflow in WhatsApp could result in remote code execution in an established video call.

CVE-2022-29464
🔥 KEV Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
94.4%
2022 50 PoCs

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and

CVE-2022-0748
post-loader Web
9.8
CRITICAL
EPSS
1.2%
2022 1 PoC

The package post-loader from 0.0.0 are vulnerable to Arbitrary Code Execution which uses a markdown parser in an unsafe way so that any javascript code inside the markdown input files gets evaluated and executed.

CVE-2022-44136
Software Genérico Web
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

CVE-2022-34270
Software Genérico General
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.

CVE-2022-40471
Software Genérico Web
9.8
CRITICAL
EPSS
90.3%
2022 3 PoCs

Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

CVE-2022-33321
PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE PV-DR006L-SET-M Web
9.8
CRITICAL
EPSS
0.8%
2022 CWE-319 1 PoC

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unaut

CVE-2022-43138
Software Genérico Web
9.8
CRITICAL
EPSS
0.3%
2022 1 PoC

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

CVE-2022-41138
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.