Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2022-37128 In D-Link DIR-816 A2_v1.10CNB04.img the network can be initialized without authentication via /goform/wizard_end. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36202 Doctor's Appointment System1.0 is vulnerable to Incorrect Access Control via edoc/patient/settings.php. The settings.php is affected by Broken Access Control (IDOR) via id= parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36201 Doctorβs Appointment System v1.0 is vulnerable to Blind SQLi via settings.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-3385 Advantech R-SeeNet Versions 2.4.17 and prior are vulnerable to a stack-based buffer overflow. An unauthorized attacker can remotely overflow the stack buffer and enable remote code execution. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-3095 The implementation of backslash parsing in the Dart URI class for versions prior to 2.18 and Flutter versions prior to 3.30 differs from the WhatWG URL standards. Dart uses the RFC 3986 syntax, which ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-39365 Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-39345 Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-39312 Dataease is an open source data visualization analysis tool. Dataease prior to 1.15.2 has a deserialization vulnerability. In Dataease, the Mysql data source in the data source function can customize ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-3754 Weak Password Requirements in GitHub repository thorsten/phpmyfaq prior to 3.1.8. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-35877 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can le... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-35876 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can le... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-35875 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can le... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-35874 Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can le... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-35244 A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corrupt... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-33938 A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-33189 An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command executi... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-33150 An OS command injection vulnerability exists in the js_package install functionality of Robustel R1510 3.1.16. A specially-crafted network request can lead to arbitrary command execution. An attacker ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-32773 An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38394 Use of hard-coded credentials for the telnet server of CentreCOM AR260S V2 firmware versions prior to Ver.3.3.7 allows a remote unauthenticated attacker to execute an arbitrary OS command. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-33941 PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script exec... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36588 In D-Link DAP1650 v1.04 firmware, the fileaccess.cgi program in the firmware has a buffer overflow vulnerability caused by strncpy. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36586 In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, there is a buffer overflow vulnerability caused by strcpy in function 0x869f4 in the httpd binary. | 9.8 | CRITICAL | β | 0 |
| CVE-2021-34236 Buffer Overflow in Netgear R8000 Router with firmware v1.0.4.56 allows remote attackers to execute arbitrary code or cause a denial-of-service by sending a crafted POST to '/bd_genie_create_account.cg... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36585 In Tenda G3 US_G3V3.0br_V15.11.0.6(7663)_EN_TDE, in httpd binary, the addDhcpRule function has a buffer overflow caused by sscanf. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38250 Nagios XI v5.8.6 was discovered to contain a SQL injection vulnerability via the mib_name parameter at the Manage MIBs page. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38314 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the urls parameter at /goform/saveParentControlInfo. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38313 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/saveParentControlInfo. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38312 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetIpMacBind. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38311 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the time parameter at /goform/PowerSaveSet. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-2475 Haas Controller version 100.20.000.1110 has insufficient granularity of access control when using the "Ethernet Q Commands" service. Any user is able to write macros into registers outside of the auth... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38310 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetStaticRouteCfg. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38309 Tenda AC18 router v15.03.05.19 and v15.03.05.05 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-1368 The Cognex 3D-A1000 Dimensioning System in firmware version 1.0.3 (3354) and prior is vulnerable to CWE-306: Missing Authentication for Critical Function, which allows unauthorized users to change the... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-36663 Gluu Oxauth before v4.4.1 allows attackers to execute blind SSRF (Server-Side Request Forgery) attacks via a crafted request_uri parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-31789 An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious reques... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-2474 Authentication is currently unsupported in Haas Controller version 100.20.000.1110 when using the βEthernet Q Commandsβ service, which allows any user on the same network segment as the controller (ev... | 9.8 | CRITICAL | β | 0 |
| CVE-2020-21516 There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-2143 The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-26447 In BT firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-40111 In TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 in the shadow.sample file, root is hardcoded in the firmware. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-34500 The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-34501 The bin-collection package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-40109 TOTOLINK A3002R TOTOLINK-A3002R-He-V1.1.1-B20200824.0128 is vulnerable to Insecure Permissions via binary /bin/boa. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-37843 In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability. | 9.8 | CRITICAL | β | 0 |
| CVE-2024-42533 SQL injection vulnerability in the authentication module in Convivance StandVoice 4.5 through 6.2 allows remote attackers to execute arbitrary code via the GEST_LOGIN parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-34509 The wikifaces package in PyPI v1.0 included a code execution backdoor inserted by a third party. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-37842 In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-34981 The PyCrowdTangle package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-34982 The eziod package in PyPI before v0.0.1 included a code execution backdoor inserted by a third party. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-34983 The scu-captcha package in PyPI v0.0.1 to v0.0.4 included a code execution backdoor inserted by a third party. | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.