94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1810
publify/publify General
9.9
CRITICAL
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository publify/publify prior to 9.2.9.

CVE-2022-26518
InRouter302 Networking
9.9
CRITICAL
EPSS
6.9%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the console infactory_net functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-25759
convert-svg-core General
9.9
CRITICAL
EPSS
2.0%
2022 1 PoC

The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.

CVE-2022-21391
Communications Billing and Revenue Management Web Database
9.9
CRITICAL
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communicat

CVE-2022-41267
BusinessObjects Business Intelligence Platform General
9.9
CRITICAL
EPSS
0.5%
2022 CWE-434 1 PoC

SAP Business Objects Platform - versions 420, and 430, allows an attacker with normal BI user privileges to upload/replace any file on Business Objects server at the operating system level, enabling the attacker to take full control of the system causing a high impact on confidentiality, integrity, and availability of the application.

CVE-2022-1571
neorazorx/facturascripts Web
9.9
CRITICAL
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...

CVE-2022-25995
InRouter302 Networking
9.9
CRITICAL
EPSS
1.9%
2022 CWE-489 1 PoC

A command execution vulnerability exists in the console inhand functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-2471
CS-CV248 General
9.9
CRITICAL
EPSS
1.0%
2022 CWE-121 1 PoC

Stack-based Buffer Overflow vulnerability in the EZVIZ Motion Detection component as used in camera models CS-CV248, CS-C6N-A0-1C2WFR, CS-DB1C-A0-1E2W2FR, CS-C6N-B0-1G2WF, CS-C3W-A0-3H4WFRL allows a remote attacker to execute remote code on the device. This issue affects: EZVIZ CS-CV248 versions prior to 5.2.3 build 220725. EZVIZ CS-C6N-A0-1C2WFR versions prior to 5.3.0 build 220428. EZVIZ CS-DB1C-A0-1E2W2FR versions prior to 5.3.0 build 220802. EZVIZ CS-C6N-B0-1G2WF versions prior to 5.3.0 build 220712. EZVIZ CS-C3W-A0-3H4WFRL versions prior to 5.3.5 build 220723.

CVE-2022-44588
Cryptocurrency Widgets Pack Web Database Windows ⚡ nuclei
9.9
CRITICAL
EPSS
34.7%
2022 CWE-89 0 PoCs

Unauth. SQL Injection vulnerability in Cryptocurrency Widgets Pack Plugin <=1.8.1 on WordPress.

CVE-2022-24663
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
2.1%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress shortcodes, which can be used by any authenticated user.

CVE-2022-2884
GitLab DevOps Web
9.9
CRITICAL
EPSS
69.0%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVE-2022-26782
InRouter302 Web Networking
9.9
CRITICAL
EPSS
1.3%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_set_item` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-1509
hestiacp/hestiacp General
9.9
CRITICAL
EPSS
1.7%
2022 CWE-77 1 PoC

Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.

CVE-2025-69691
Software Genérico Web
9.9
CRITICAL
EPSS
0.0%
2025 1 PoC

Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally allowed to execute PHP code.

CVE-2007-2422
Software Genérico Web
9.8
CRITICAL
EPSS
1.0%
2007 1 PoC

Multiple PHP remote file inclusion vulnerabilities in Modules Builder (modbuild) 4.1 for Comdev One Admin allow remote attackers to execute arbitrary PHP code via a URL in the path[docroot] parameter to (1) config-bak.php or (2) config.php. NOTE: CVE disputes this vulnerability because the unmodified scripts set the applicable variable to the empty string; reasonable modified copies would use a fixed pathname string

CVE-2007-4039
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2007 1 PoC

Argument injection vulnerability involving Mozilla, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670.

CVE-2007-2534
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.8%
2007 1 PoC

Multiple SQL injection vulnerabilities in admin.php in phpHoo3 allow remote attackers to execute arbitrary SQL commands via the (1) ADMIN_USER (USER) and (2) ADMIN_PASS (PASS) parameters during a login. NOTE: CVE disputes this vulnerability, since ADMIN_USER/ADMIN_PASS are initialized before use

CVE-2007-2020
Software Genérico Web
9.8
CRITICAL
EPSS
4.0%
2007 1 PoC

Unspecified vulnerability in administration.php in xodagallery allows remote attackers to execute arbitrary code via the cmd parameter. NOTE: CVE disputes this vulnerability because administration.php does not use the cmd parameter for inclusion

CVE-2007-3194
Software Genérico Web
9.8
CRITICAL
EPSS
1.0%
2007 1 PoC

Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) config.php; (2) db.php, (3) template.php, (4) functions.php, and (5) classes.php in includes/; (6) viewmode.php; and (7) blog_body.php. NOTE: another researcher disputes the vulnerability because the files are protected against direct requests, contain no relevant include statements, or do not exist

CVE-2007-4559
Software Genérico General
9.8
CRITICAL
EPSS
89.7%
2007 2 PoCs

Directory traversal vulnerability in the (1) extract and (2) extractall functions in the tarfile module in Python allows user-assisted remote attackers to overwrite arbitrary files via a .. (dot dot) sequence in filenames in a TAR archive, a related issue to CVE-2001-1267.