7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-4866
usememos/memos Web
9.8
CRITICAL
EPSS
0.5%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-46887
Software Genérico Web Database
9.8
CRITICAL
EPSS
2.8%
2022 1 PoC

Multiple SQL injection vulnerabilities in NexusPHP before 1.7.33 allow remote attackers to execute arbitrary SQL commands via the conuser[] parameter in takeconfirm.php; the delcheater parameter in cheaterbox.php; or the usernw parameter in nowarn.php.

CVE-2022-47118
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the wepkey1 parameter at /goform/WifiBasicSet.

CVE-2022-4693
User Verification Web Windows
9.8
CRITICAL
EPSS
10.2%
2022 1 PoC

The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.

CVE-2022-42245
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 1 PoC

Dreamer CMS 4.0.01 is vulnerable to SQL Injection.

CVE-2022-44204
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

CVE-2022-48323
Software Genérico Web ⚡ nuclei
9.8
CRITICAL
EPSS
86.9%
2022 1 PoC

Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a path traversal issue. A remote and unauthenticated attacker can execute arbitrary programs on the victim host by sending a crafted HTTP request, as demonstrated by /check?cmd=ping../ followed by the pathname of the powershell.exe program.

CVE-2022-24086
🔥 KEV Magento Commerce General ⚡ nuclei
9.8
CRITICAL
EPSS
93.7%
2022 CWE-20 15 PoCs

Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.

CVE-2022-44006
Software Genérico General
9.8
CRITICAL
EPSS
5.7%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to improper validation or sanitization of upload filenames, an externally reachable, unauthenticated update function permits writing files outside the intended target location. Achieving remote code execution is possible, e.g., by uploading an executable file.

CVE-2022-28755
Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) Windows
9.6
CRITICAL
EPSS
0.5%
2022 CWE-20 1 PoC

The Zoom Client for Meetings (for Android, iOS, Linux, macOS, and Windows) before version 5.11.0 are susceptible to a URL parsing vulnerability. If a malicious Zoom meeting URL is opened, the malicious link may direct the user to connect to an arbitrary network address, leading to additional attacks including the potential for remote code execution through launching executables from arbitrary paths.

CVE-2022-26842
AVideo Web
9.6
CRITICAL
EPSS
9.5%
2022 CWE-79 1 PoC

A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.

CVE-2022-2733
openemr/openemr Web ⚡ nuclei
9.6
CRITICAL
EPSS
91.7%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.1.

CVE-2022-24010
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cwmpd binary.

CVE-2022-21178
LinkHub Mesh Wifi Cloud
9.6
CRITICAL
EPSS
4.8%
2022 CWE-78 1 PoC

An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-24015
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.6%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the log_upload binary.

CVE-2022-32771
AVideo Web ⚡ nuclei
9.6
CRITICAL
EPSS
10.0%
2022 CWE-79 1 PoC

A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can get an authenticated user to send a crafted HTTP request to trigger this vulnerability.This vulnerability arrises from the "success" parameter which is inserted into the document with insufficient sanitization.

CVE-2022-3152
phpfusion/phpfusion Web
9.6
CRITICAL
EPSS
0.3%
2022 CWE-620 1 PoC

Unverified Password Change in GitHub repository phpfusion/phpfusion prior to 9.10.20.

CVE-2022-24007
LinkHub Mesh Wifi General
9.6
CRITICAL
EPSS
0.5%
2022 CWE-120 1 PoC

A buffer overflow vulnerability exists in the GetValue functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted configuration value can lead to a buffer overflow. An attacker can modify a configuration value to trigger this vulnerability.This vulnerability represents all occurances of the buffer overflow vulnerability within the cfm binary.

CVE-2022-1883
camptocamp/terraboard Database ⚡ nuclei
9.6
CRITICAL
EPSS
62.0%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository camptocamp/terraboard prior to 2.2.0.

CVE-2022-0173
radareorg/radare2 General
9.6
CRITICAL
EPSS
0.4%
2022 CWE-125 1 PoC

radare2 is vulnerable to Out-of-bounds Read