Vulnerabilidades CVE
Base de datos de vulnerabilidades CVE enriquecida con datos de CISA KEV y NVD
| CVE ID | CVSS | Severidad | KEV | Avistamientos |
|---|---|---|---|---|
| CVE-2022-39185 EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46404 A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may ... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-3515 A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specia... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-39184 EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-44832 D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46609 Python3-RESTfulAPI commit d9907f14e9e25dcdb54f5b22252b0e9452e3970e and e772e0beee284c50946e94c54a1d43071ca78b74 was discovered to contain a code execution backdoor via the request package. This vulner... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46996 vSphere_selfuse commit 2a9fe074a64f6a0dd8ac02f21e2f10d66cac5749 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive use... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46997 Passhunt commit 54eb987d30ead2b8ebbf1f0b880aa14249323867 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user infor... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47864 Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47862 Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47861 Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47860 Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47859 Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47866 Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-47865 Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-37832 Mutiny 7.2.0-10788 suffers from Hardcoded root password. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46071 There is SQL Injection vulnerability at Helmet Store Showroom v1.0 Login Page. This vulnerability can be exploited to bypass admin access. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46072 Helmet Store Showroom v1.0 vulnerable to unauthenticated SQL Injection. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46255 An improper limitation of a pathname to a restricted directory vulnerability was identified in GitHub Enterprise Server that enabled remote code execution. A check was added within Pages to ensure the... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46955 Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=save_queue. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46954 Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/ajax.php?action=delete_transaction. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46316 A thread security vulnerability exists in the authentication process. Successful exploitation of this vulnerability may affect data integrity, confidentiality, and availability. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-31702 vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authent... | 9.8 | CRITICAL | β | 0 |
| CVE-2022-38488 logrocket-oauth2-example through 2020-05-27 allows SQL injection via the /auth/register username parameter. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46020 WBCE CMS v1.5.4 can implement getshell by modifying the upload file type. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46538 Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-40624 pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-46421 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Prov... | 9.8 | CRITICAL | β | 0 |
| CVE-2021-33420 A deserialization issue discovered in inikulin replicator before 1.0.4 allows remote attackers to run arbitrary code via the fromSerializable function in TypedArray object. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-44109 pdftojson commit 94204bb was discovered to contain a stack overflow via the component Stream::makeFilter(char*, Stream*, Object*, int). | 9.8 | CRITICAL | β | 0 |
| CVE-2022-44108 pdftojson commit 94204bb was discovered to contain a stack overflow via the component Object::copy(Object*):Object.cc. | 9.8 | CRITICAL | β | 0 |
| CVE-2022-40434 Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6414 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via perfil.php in the id and user parameters. Exploitation of this vulnerab... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-46480 An issue in OwnCast v.0.1.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via the authHost parameter of the indieauth function. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-48804 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a co... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6410 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via editprofile.php in multiple parameters. Exploitation of this vulnerabil... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6411 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via home.php in the update parameter. Exploitation of this vulnerability co... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6412 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photo.php in multiple parameters. Exploitation of this vulnerability co... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6413 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via photos.php in the id and user parameters. Exploitation of this vulnerab... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-49042 Heap Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the schedStartTime parameter or the schedEndTime parameter in the function setSchedWifi. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-49040 An issue in Tneda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the adslPwd parameter in the form_fast_setting_internet_set function. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-47397 WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-41998 Arcserve UDP prior to 9.2 contained a vulnerability in theΒ com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-48803 In TOTOLINK X6000R V9.4.0cu.852_B20230719, the shttpd file, sub_4119A0 function obtains fields from the front-end through Uci_ Set_ The Str function when passed to the CsteSystem function creates a co... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6415 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signin.php in the user parameter. Exploitation of this vulnerability co... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-49046 Stack Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the devName parameter in the function formAddMacfilterRule. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-49043 Buffer Overflow vulnerability in Tenda AX1803 v.1.0.0.1 allows a remote attacker to execute arbitrary code via the wpapsk_crypto parameter in the function fromSetWirelessRepeat. | 9.8 | CRITICAL | β | 0 |
| CVE-2023-6416 A vulnerability has been reported in Voovi Social Networking Script that affects version 1.0 and consists of a SQL injection via signup2.php in the emailadd parameter. Exploitation of this vulnerabili... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-5941 In versions of FreeBSD 12.4-RELEASE prior to 12.4-RELEASE-p7 and FreeBSD 13.2-RELEASE prior to 13.2-RELEASE-p5 the __sflush() stdio function in libc does not correctly update FILE objects' write space... | 9.8 | CRITICAL | β | 0 |
| CVE-2023-41999 An authentication bypass exists in Arcserve UDP prior to version 9.2. An unauthenticated, remote attacker can obtain a valid authentication identifier that allows them to authenticate to the managemen... | 9.8 | CRITICAL | β | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.