7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3574
WPForms Pro Web Windows
9.8
CRITICAL
EPSS
1.3%
2022 CWE-1236 1 PoC

The WPForms Pro WordPress plugin before 1.7.7 does not validate its form data when generating the exported CSV, which could lead to CSV injection.

CVE-2022-44204
Software Genérico General
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

D-Link DIR3060 DIR3060A1_FW111B04.bin is vulnerable to Buffer Overflow.

CVE-2022-31056
glpi Database
9.8
CRITICAL
EPSS
5.2%
2022 CWE-89 1 PoC

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all assistance forms (Ticket/Change/Problem) permit sql injection on the actor fields. This issue has been resolved in version 10.0.2 and all affected users are advised to upgrade.

CVE-2022-46581
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.

CVE-2022-46640
Software Genérico Web
9.8
CRITICAL
EPSS
6.8%
2022 1 PoC

Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.

CVE-2022-3634
Contact Form 7 Database Addon Web Windows
9.8
CRITICAL
EPSS
1.0%
2022 1 PoC

The Contact Form 7 Database Addon WordPress plugin before 1.2.6.5 does not validate data when output it back in a CSV file, which could lead to CSV injection

CVE-2022-40434
Software Genérico General
9.8
CRITICAL
EPSS
0.5%
2022 1 PoC

Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.

CVE-2022-45710
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule parameters in the formSetDebugCfg function.

CVE-2022-40797
Software Genérico Web
9.8
CRITICAL
EPSS
12.6%
2022 1 PoC

Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.json only blocks .php, .php4, and .php5 files. (Visiting any .phar file invokes the PHP interpreter in some realistic web-server configurations.)

CVE-2022-4047
Return Refund and Exchange For WooCommerce Web Windows
9.8
CRITICAL
EPSS
73.3%
2022 2 PoCs

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.0.9 does not validate attachment files to be uploaded via an AJAX action available to unauthenticated users, which could allow them to upload arbitrary files such as PHP and lead to RCE

CVE-2022-44003
Software Genérico Web Database
9.8
CRITICAL
EPSS
0.2%
2022 2 PoCs

An issue was discovered in BACKCLICK Professional 5.9.63. Due to insufficient escaping of user-supplied input, the application is vulnerable to SQL injection at various locations.

CVE-2022-45712
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 3 PoCs

IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsForward function.

CVE-2022-3915
Dokan Web Database Windows
9.8
CRITICAL
EPSS
3.2%
2022 1 PoC

The Dokan WordPress plugin before 3.7.6 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users

CVE-2022-4298
Wholesale Market Web Windows
9.8
CRITICAL
EPSS
55.7%
2022 1 PoC

The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.

CVE-2022-40471
Software Genérico Web
9.8
CRITICAL
EPSS
90.3%
2022 3 PoCs

Remote Code Execution in Clinic's Patient Management System v 1.0 allows Attacker to Upload arbitrary php webshell via profile picture upload functionality in users.php

CVE-2022-44190
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

Netgear R7000P V1.3.1.64 is vulnerable to Buffer Overflow via parameter enable_band_steering.

CVE-2022-45637
Software Genérico General
9.8
CRITICAL
EPSS
0.7%
2022 1 PoC

An insecure password reset issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 service via insecure expiry mechanism.

CVE-2022-43001
Software Genérico General
9.8
CRITICAL
EPSS
1.4%
2022 1 PoC

D-Link DIR-816 A2 1.10 B05 was discovered to contain a stack overflow via the pskValue parameter in the setSecurity function.

CVE-2022-44015
Software Genérico Database
9.8
CRITICAL
EPSS
0.9%
2022 1 PoC

An issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can inject raw SQL queries. By activating MSSQL features, the attacker is able to execute arbitrary commands on the MSSQL server via the xp_cmdshell extended procedure.

CVE-2022-46601
Software Genérico General
9.8
CRITICAL
EPSS
0.4%
2022 1 PoC

TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the setbg_num parameter in the icp_setbg_img (sub_41DD68) function.