7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-32763
lansweeper Web
9.1
CRITICAL
EPSS
0.9%
2022 CWE-184 1 PoC

A cross-site scripting (xss) sanitization vulnerability bypass exists in the SanitizeHtml functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-33150
R1510 General
9.1
CRITICAL
EPSS
1.2%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-2064
nocodb/nocodb General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.

CVE-2022-28703
lansweeper Web
9.1
CRITICAL
EPSS
3.9%
2022 CWE-80 1 PoC

A stored cross-site scripting vulnerability exists in the HdConfigActions.aspx altertextlanguages functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-41561
TIBCO JasperReports Server Cloud
9.1
CRITICAL
EPSS
4.2%
2022 1 PoC

The JNDI Data Sources component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for Microsoft Azure, and TIBCO JasperReports Server for Microsoft Azure contains an easily exploitable vulnerability that allows a privileged/administrative attacker with network access to execute Remote Code Execution to obtain a reverse shell on the affected system.

CVE-2022-1411
yetiforcecompany/yetiforcecrm General
9.1
CRITICAL
EPSS
0.3%
2022 CWE-434 1 PoC

Unrestructed file upload in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0. Attacker can send malicious files to the victims is able to retrieve the stored data from the web application without that data being made safe to render in the browser and steals victim's cookie leads to account takeover.

CVE-2022-31678
VMware Cloud Foundation (NSX-V) Cloud ⚡ nuclei
9.1
CRITICAL
EPSS
86.0%
2022 1 PoC

VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure.

CVE-2022-1399
CMDB General
9.1
CRITICAL
EPSS
0.6%
2022 CWE-88 1 PoC

An Argument Injection or Modification vulnerability in the "Change Secret" username field as used in the Discovery component of Device42 CMDB allows a local attacker to run arbitrary code on the appliance with root privileges. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-1162
GitLab DevOps Windows ⚡ nuclei
9.1
CRITICAL
EPSS
87.6%
2022 3 PoCs

A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE versions 14.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowing attackers to potentially take over accounts

CVE-2022-21723
pjproject General
9.1
CRITICAL
EPSS
0.5%
2022 CWE-125 1 PoC

PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE. In versions 2.11.1 and prior, parsing an incoming SIP message that contains a malformed multipart can potentially cause out-of-bound read access. This issue affects all PJSIP users that accept SIP multipart. The patch is available as commit in the `master` branch. There are no known workarounds.

CVE-2022-33328
R1510 Web
9.1
CRITICAL
EPSS
3.5%
2022 CWE-78 1 PoC

Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0. A specially-crafted network packets can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.The `/ajax/remove/` API is affected by a command injection vulnerability.

CVE-2022-43216
Software Genérico Database
9.1
CRITICAL
EPSS
0.2%
2022 1 PoC

AbrhilSoft Employee's Portal before v5.6.2 was discovered to contain a SQL injection vulnerability in the login page.

CVE-2022-42484
FreshTomato Web
9.1
CRITICAL
EPSS
0.6%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of FreshTomato 2022.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-45891
Software Genérico General
9.1
CRITICAL
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).

CVE-2022-46836
Checkmk Web
9.1
CRITICAL
EPSS
2.1%
2022 CWE-20 1 PoC

PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.

CVE-2022-41923
grails-spring-security-core Web
9.1
CRITICAL
EPSS
0.3%
2022 CWE-269 1 PoC

Grails Spring Security Core plugin is vulnerable to privilege escalation. The vulnerability allows an attacker access to one endpoint (i.e. the targeted endpoint) using the authorization requirements of a different endpoint (i.e. the donor endpoint). In some Grails framework applications, access to the targeted endpoint will be granted based on meeting the authorization requirements of the donor endpoint, which can result in a privilege escalation attack. This vulnerability has been patched in grails-spring-security-core versions 3.3.2, 4.0.5 and 5.1.1. Impacted Applications: Grails Spring Sec

CVE-2022-1811
publify/publify General
9.1
CRITICAL
EPSS
0.2%
2022 CWE-434 1 PoC

Unrestricted Upload of File with Dangerous Type in GitHub repository publify/publify prior to 9.2.9.

CVE-2022-39811
Software Genérico General
9.1
CRITICAL
EPSS
0.2%
2022 1 PoC

Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui/advancedsettings.jsp and NMSCIWebGui/SaveFileUploader. By not verifying permissions for access to resources, it allows an attacker to view pages that are not allowed, and modify the system configuration, bypassing all controls (without checking for user identity).

CVE-2022-29830
GX Works3 Cloud
9.1
CRITICAL
EPSS
1.2%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z, and Motion Control Setting(GX Works3 related software) versions from 1.000A to 1.065T allows a remote unauthenticated attacker to disclose or tamper with sensitive information. As a result, unauthenticated attackers may obtain information about project files illegally.