7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-48592
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-39066
MF286R Database
8.8
HIGH
EPSS
51.1%
2022 1 PoC

There is a SQL injection vulnerability in ZTE MF286R. Due to insufficient validation of the input parameters of the phonebook interface, an authenticated attacker could use the vulnerability to execute arbitrary SQL injection.

CVE-2022-0512
unshiftio/url-parse General
8.8
HIGH
EPSS
0.0%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in NPM url-parse prior to 1.5.6.

CVE-2022-50694
Impact/Pulse/First Web Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username parameter to bypass authentication and potentially access unauthorized database information.

CVE-2022-50892
VIAVIWEB Wallpaper Admin Database
8.8
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

VIAVIWEB Wallpaper Admin 1.0 contains a SQL injection vulnerability that allows attackers to bypass authentication by manipulating login credentials. Attackers can exploit the login page by injecting 'admin' or 1=1-- - payload to gain unauthorized access to the administrative interface.

CVE-2022-50805
Senayan Library Management System Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive information.

CVE-2022-21201
LinkHub Mesh Wifi Cloud
8.8
HIGH
EPSS
0.1%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the confers ucloud_add_node_new functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-0520
radareorg/radare2 General
8.8
HIGH
EPSS
0.2%
2022 CWE-416 1 PoC

Use After Free in NPM radare2.js prior to 5.6.2.

CVE-2022-26485
🔥 KEV Firefox General
8.8
HIGH
EPSS
7.2%
2022 1 PoC

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CVE-2022-35135
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.

CVE-2022-40250
Aptio General
8.8
HIGH
EPSS
0.1%
2022 CWE-121 2 PoCs

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass securi

CVE-2022-36804
🔥 KEV Bitbucket Server Web ⚡ nuclei
8.8
HIGH
EPSS
94.4%
2022 26 PoCs

Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8.1.0 before version 8.1.3, and from version 8.2.0 before version 8.2.2, and from version 8.3.0 before 8.3.1 allows remote attackers with read permissions to a public or private Bitbucket repository to execute arbitrary code by sending a malicious HTTP request. This vulnerability was reported via our Bug Bounty Program by TheGrandPew.

CVE-2022-3911
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more Web Windows
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The iubenda WordPress plugin before 3.3.3 does does not have authorisation and CSRF in an AJAX action, and does not ensure that the options to be updated belong to the plugin as long as they are arrays. As a result, any authenticated users, such as subscriber can grant themselves any privileges, such as edit_plugins etc

CVE-2022-46435
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

An issue in the firmware update process of TP-Link TL-WR941ND V2/V3 up to 3.13.9 and TL-WR941ND V4 up to 3.12.8 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVE-2022-45942
Software Genérico Web
8.8
HIGH
EPSS
3.9%
2022 1 PoC

A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

CVE-2022-41128
🔥 KEV Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
39.2%
2022 1 PoC

Windows Scripting Languages Remote Code Execution Vulnerability

CVE-2022-32893
🔥 KEV Safari General
8.8
HIGH
EPSS
0.2%
2022 4 PoCs

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.

CVE-2022-22756
Firefox General
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-3849
WP User Merger Web Database Windows
8.8
HIGH
EPSS
0.5%
2022 2 PoCs

The WP User Merger WordPress plugin before 1.5.3 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as admin