94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2011-10011
WeBid Web
10.0
CRITICAL
EPSS
57.5%
2011 CWE-94 4 PoCs

WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.

CVE-2011-10018
Forum Software Web
10.0
CRITICAL
EPSS
53.0%
2011 CWE-912 3 PoCs

myBB version 1.6.4 was distributed with an unauthorized backdoor embedded in the source code. The backdoor allowed remote attackers to execute arbitrary PHP code by injecting payloads into a specially crafted collapsed cookie. This vulnerability was introduced during packaging and was not part of the intended application logic. Exploitation requires no authentication and results in full compromise of the web server under the context of the web application.

CVE-2011-10013
Issue Tracking System Web
10.0
CRITICAL
EPSS
63.7%
2011 CWE-94 3 PoCs

Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a failed access check, allowing unauthenticated users to reach admin-only functionality. This can be exploited via plugins.php to inject and execute arbitrary PHP code.

CVE-2011-10019
Spreecommerce General
10.0
CRITICAL
EPSS
69.3%
2011 CWE-94 2 PoCs

Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its search functionality. The application fails to properly sanitize input passed via the search[send][] parameter, which is dynamically invoked using Ruby’s send method. This allows attackers to execute arbitrary shell commands on the server without authentication.

CVE-2011-10017
Snort Report Web
10.0
CRITICAL
EPSS
63.5%
2011 CWE-78 2 PoCs

Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and can result in full compromise of the underlying system.

CVE-2022-0735
GitLab DevOps ⚡ nuclei
10.0
CRITICAL
EPSS
57.4%
2022 1 PoC

An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an information disclosure vulnerability using quick actions commands.

CVE-2022-22947
🔥 KEV Spring Cloud Gateway Web Cloud ⚡ nuclei
10.0
CRITICAL
EPSS
94.5%
2022 CWE-94 76 PoCs

In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.

CVE-2022-1986
gogs/gogs General
10.0
CRITICAL
EPSS
9.2%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

CVE-2022-20700
🔥 KEV Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
25.8%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-33192
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
3.6%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_SSID` and `WL_SSID_HEX` configuration values in the function at offset `0x1c7d28` of firmware 6.9Z.

CVE-2022-21431
Communications Billing and Revenue Management Database
10.0
CRITICAL
EPSS
1.9%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Or

CVE-2022-21389
Communications Billing and Revenue Management Web Database
10.0
CRITICAL
EPSS
1.6%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communica

CVE-2022-21941
iSTAR Ultra General
10.0
CRITICAL
EPSS
19.7%
2022 CWE-77 1 PoC

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

CVE-2022-20710
Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
1.7%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-43604
OpENer General
10.0
CRITICAL
EPSS
7.6%
2022 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the GetAttributeList attribute_count_request functionality of EIP Stack Group OpENer development commit 58ee13c. A specially crafted EtherNet/IP request can lead to an out-of-bounds write, potentially causing the server to crash or allow for remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.

CVE-2022-20703
🔥 KEV Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
2.0%
2022 CWE-121 1 PoC

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-20699
🔥 KEV Cisco Small Business RV Series Router Firmware Networking
10.0
CRITICAL
EPSS
90.0%
2022 CWE-121 7 PoCs

Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.

CVE-2022-21275
Communications Billing and Revenue Management Web Database
10.0
CRITICAL
EPSS
1.6%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communica

CVE-2022-4361
keycloak Web
10.0
CRITICAL
EPSS
1.3%
2022 CWE-81 1 PoC

Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.

CVE-2022-30541
iota All-In-One Security Kit General
10.0
CRITICAL
EPSS
1.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability.