7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-50932
Kyocera Command Center RX General
8.7
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exploit the issue by sending requests like /js/../../../../.../etc/passwd%00.jpg (null-byte appended traversal) to access critical files such as /etc/passwd and /etc/shadow.

CVE-2022-38123
GateManager General
8.7
HIGH
EPSS
0.5%
2022 CWE-20 1 PoC

Improper Input Validation of plugin files in Administrator Interface of Secomea GateManager allows a server administrator to inject code into the GateManager interface. This issue affects: Secomea GateManager versions prior to 10.0.

CVE-2022-50897
mPDF General
8.7
HIGH
EPSS
0.0%
2022 CWE-98 1 PoC

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

CVE-2022-50926
WAGO 750-8212 PFC200 General
8.7
HIGH
EPSS
0.1%
2022 CWE-565 1 PoC

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's 'name' and 'roles' parameters to elevate from ordinary user to administrative privileges without authentication.

CVE-2022-28127
R1510 Web
8.7
HIGH
EPSS
5.3%
2022 CWE-20 1 PoC

A data removal vulnerability exists in the web_server /action/remove/ API functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary file deletion. An attacker can send a sequence of requests to trigger this vulnerability.

CVE-2022-50793
Impact/Pulse/First Web
8.7
HIGH
EPSS
0.8%
2022 CWE-78 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute arbitrary system commands with www-data user privileges.

CVE-2022-41566
TIBCO EBX Add-ons Web
8.7
HIGH
EPSS
0.7%
2022 1 PoC

The server component of TIBCO Software Inc.'s TIBCO EBX Add-ons contains an easily exploitable vulnerability that allows a low privileged attacker with network access to execute stored XSS on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO EBX Add-ons: versions 5.6.0 and below.

CVE-2022-23425
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper input validation in Exynos baseband prior to SMR Feb-2022 Release 1 allows attackers to send arbitrary NAS signaling messages with fake base station.

CVE-2022-4841
usememos/memos Web
8.6
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-20848
Cisco IOS XE Software Networking
8.6
HIGH
EPSS
1.6%
2022 CWE-399 1 PoC

A vulnerability in the UDP processing functionality of Cisco IOS XE Software for Embedded Wireless Controllers on Catalyst 9100 Series Access Points could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of UDP datagrams. An attacker could exploit this vulnerability by sending malicious UDP datagrams to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

CVE-2022-2713
cockpit-hq/cockpit General
8.6
HIGH
EPSS
1.1%
2022 CWE-613 1 PoC

Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0.

CVE-2022-1026
Multifunction Printer Net Viewer General ⚡ nuclei
8.6
HIGH
EPSS
86.8%
2022 CWE-522 2 PoCs

Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export function.

CVE-2022-50939
e107 CMS Web
8.6
HIGH
EPSS
0.7%
2022 CWE-22 1 PoC

e107 CMS version 3.2.1 contains a critical file upload vulnerability that allows authenticated administrators to override arbitrary server files through path traversal. The vulnerability exists in the Media Manager's remote URL upload functionality (image.php) where the upload_caption parameter is not properly sanitized. An attacker with administrative privileges can use directory traversal sequences (../../../) in the upload_caption field to overwrite critical system files outside the intended upload directory. This can lead to complete compromise of the web application by overwriting configu

CVE-2022-4799
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-22774
TIBCO Managed File Transfer Command Center General
8.6
HIGH
EPSS
0.7%
2022 1 PoC

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Internet Server, and TIBCO Managed File Transfer Internet Server contains an easily exploitable vulnerability that allows an unauthenticated attacker with network access to execute XML External Entity (XXE) attacks on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center: versions 8.3.1 and below, TIBCO Managed File Transfer Command Center: versions 8.4.

CVE-2022-50907
e107 CMS Web
8.6
HIGH
EPSS
0.5%
2022 CWE-434 1 PoC

e107 CMS version 3.2.1 contains a file upload vulnerability that allows authenticated administrative users to bypass upload restrictions and execute PHP files. Attackers can upload malicious PHP files to parent directories by manipulating the upload URL parameter, enabling remote code execution through the Media Manager import feature.

CVE-2022-50909
Algo 8028 General
8.6
HIGH
EPSS
0.3%
2022 CWE-78 1 PoC

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.

CVE-2022-29477
iota All-In-One Security Kit Web
8.6
HIGH
EPSS
0.3%
2022 CWE-798 1 PoC

An authentication bypass vulnerability exists in the web interface /action/factory* functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP header can lead to authentication bypass. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2022-33719
Samsung Mobile Devices General
8.6
HIGH
EPSS
0.2%
2022 CWE-20 1 PoC

Improper input validation in baseband prior to SMR Aug-2022 Release 1 allows attackers to cause integer overflow to heap overflow.

CVE-2022-43939
🔥 KEV Pentaho Business Analytics Server General ⚡ nuclei
8.6
HIGH
EPSS
93.3%
2022 CWE-647 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.