7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-44257
Software Genérico General
8.8
HIGH
EPSS
0.7%
2022 1 PoC

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter pppoeUser in the setOpModeCfg function.

CVE-2022-32509
Software Genérico Web
8.8
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2.

CVE-2022-44007
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to an unsafe implementation of session tracking, it is possible for an attacker to trick users into opening an authenticated user session for a session identifier known to the attacker, aka Session Fixation.

CVE-2022-22755
Firefox Web
8.8
HIGH
EPSS
0.8%
2022 2 PoCs

By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

CVE-2022-3537
Role Based Pricing for WooCommerce Web Windows
8.8
HIGH
EPSS
0.2%
2022 CWE-434 1 PoC

The Role Based Pricing for WooCommerce WordPress plugin before 1.6.2 does not have authorisation and proper CSRF checks, and does not validate files to be uploaded, allowing any authenticated users like subscriber to upload arbitrary files, such as PHP

CVE-2022-2829
yetiforcecompany/yetiforcecrm Web
8.8
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-48583
SL 1 General
8.8
HIGH
EPSS
0.5%
2022 CWE-78 1 PoC

A command injection vulnerability exists in the dashboard scheduler feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVE-2022-0935
livehelperchat/livehelperchat General
8.8
HIGH
EPSS
0.4%
2022 CWE-840 1 PoC

Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.

CVE-2022-31888
Software Genérico Web
8.8
HIGH
EPSS
2.4%
2022 1 PoC

Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.

CVE-2022-0070
log4j-cve-2021-44228-hotpatch Web
8.8
HIGH
EPSS
0.0%
2022 CWE-250 1 PoC

Incomplete fix for CVE-2021-3100. The Apache Log4j hotpatch package starting with log4j-cve-2021-44228-hotpatch-1.1-16 will now explicitly mimic the Linux capabilities and cgroups of the target Java process that the hotpatch is applied to.

CVE-2022-48598
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-32507
Software Genérico General
8.8
HIGH
EPSS
0.0%
2022 2 PoCs

An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different accounts. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4.

CVE-2022-1529
Firefox ESR Web
8.8
HIGH
EPSS
4.3%
2022 1 PoC

An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process. This vulnerability affects Firefox ESR < 91.9.1, Firefox < 100.0.2, Firefox for Android < 100.3.0, and Thunderbird < 91.9.1.

CVE-2022-44149
Software Genérico General
8.8
HIGH
EPSS
82.2%
2022 6 PoCs

The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON host field to the ping feature of the goform/sysTools component. Authentication is required

CVE-2022-30165
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
7.4%
2022 1 PoC

Windows Kerberos Elevation of Privilege Vulnerability

CVE-2022-23063
Shopizer General
8.8
HIGH
EPSS
0.3%
2022 CWE-613 1 PoC

In Shopizer versions 2.3.0 to 3.0.1 are vulnerable to Insufficient Session Expiration. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.

CVE-2022-28281
Thunderbird General
8.8
HIGH
EPSS
14.6%
2022 1 PoC

If a compromised content process sent an unexpected number of WebAuthN Extensions in a Register command to the parent process, an out of bounds write would have occurred leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox < 99, and Firefox ESR < 91.8.

CVE-2022-42098
Software Genérico Web Database
8.8
HIGH
EPSS
1.6%
2022 2 PoCs

KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.

CVE-2022-41757
Software Genérico General
8.8
HIGH
EPSS
0.5%
2022 1 PoC

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to obtain write access to read-only memory, or obtain access to already freed memory. This affects Valhall r29p0 through r38p1 before r38p2, and r39p0 before r40p0.

CVE-2022-4017
Booster for WooCommerce Web Windows
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 6.0.1, Booster Plus for WooCommerce WordPress plugin before 6.0.1, Booster Elite for WooCommerce WordPress plugin before 6.0.1 have either flawed CSRF checks or are missing them completely in numerous places, allowing attackers to make logged in users perform unwanted actions via CSRF attacks