7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-33207
iota All-In-One Security Kit Web
10.0
CRITICAL
EPSS
4.7%
2022 CWE-78 1 PoC

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability focuses on a second unsafe use of the `default_key_id` HTTP parameter to construct an OS Command at offset `0x19B234` of the `/root/hpgw` binary included in firmware 6.9Z.

CVE-2022-30534
AVideo Web
9.9
CRITICAL
EPSS
12.3%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-26780
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.9%
2022 CWE-20 1 PoC

Multiple improper input validation vulnerabilities exists in the libnvram.so nvram_import functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted file can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.An improper input validation vulnerability exists in the `httpd`'s `user_define_init` function. Controlling the `user_define_timeout` nvram variable can lead to remote code execution.

CVE-2022-2550
hestiacp/hestiacp General
9.9
CRITICAL
EPSS
8.8%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository hestiacp/hestiacp prior to 1.6.5.

CVE-2022-26510
InRouter302 Web Networking
9.9
CRITICAL
EPSS
0.5%
2022 CWE-347 1 PoC

A firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted HTTP request can lead to firmware update. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-24665
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
2.1%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via a WordPress gutenberg block by any user able to edit posts.

CVE-2022-29517
lansweeper Web
9.9
CRITICAL
EPSS
46.2%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the HelpdeskActions.aspx edittemplate functionality of Lansweeper lansweeper 10.1.1.0. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-21276
Communications Billing and Revenue Management Web Database
9.9
CRITICAL
EPSS
1.4%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.3 and 12.0.0.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Communicat

CVE-2022-37425
Software Genérico General
9.9
CRITICAL
EPSS
2.1%
2022 1 PoC

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.

CVE-2022-26420
InRouter302 Networking
9.9
CRITICAL
EPSS
9.1%
2022 CWE-78 1 PoC

An OS command injection vulnerability exists in the console infactory_port functionality of InHand Networks InRouter302 V3.5.37. A specially-crafted series of network requests can lead to remote code execution. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-1770
polonel/trudesk General
9.9
CRITICAL
EPSS
0.3%
2022 CWE-269 1 PoC

Improper Privilege Management in GitHub repository polonel/trudesk prior to 1.2.2.

CVE-2022-30547
AVideo Web
9.9
CRITICAL
EPSS
20.7%
2022 CWE-22 1 PoC

A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-46642
Software Genérico General
9.9
CRITICAL
EPSS
6.9%
2022 1 PoC

D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function.

CVE-2022-36786
DSL-224 Web Networking
9.9
CRITICAL
EPSS
0.4%
2022 1 PoC

DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.

CVE-2022-0415
gogs/gogs General ⚡ nuclei
9.9
CRITICAL
EPSS
89.6%
2022 CWE-20 1 PoC

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

CVE-2022-26085
InRouter302 Web Networking
9.9
CRITICAL
EPSS
2.7%
2022 CWE-77 1 PoC

An OS command injection vulnerability exists in the httpd wlscan_ASP functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

CVE-2022-41272
NetWeaver Process Integration Web
9.9
CRITICAL
EPSS
0.7%
2022 CWE-862 2 PoCs

An unauthenticated attacker over the network can attach to an open interface exposed through JNDI by the User Defined Search (UDS) of SAP NetWeaver Process Integration (PI) - version 7.50 and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting users and data across the entire system. This allows the attacker to have full read access to user data, make limited modifications to user data, and degrade the performance of the system, leading to a high impact on confidentiality and a limited impact on the availability and int

CVE-2022-2992
GitLab DevOps Web
9.9
CRITICAL
EPSS
93.7%
2022 3 PoCs

A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

CVE-2022-1699
causefx/organizr General
9.9
CRITICAL
EPSS
0.3%
2022 CWE-190 1 PoC

Uncontrolled Resource Consumption in GitHub repository causefx/organizr prior to 2.1.2000. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.

CVE-2022-24664
PHP Everywhere Web Windows
9.9
CRITICAL
EPSS
1.5%
2022 CWE-94 1 PoC

PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.