CVE Database

CVE-2022-34113CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue in the component /api/plugin/upload of Dataease v1.11.1 allows attackers to execute arbitrary code via a crafted plugin.

CVE-2022-34115CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-434

DataEase v1.11.1 was discovered to contain a arbitrary file write vulnerability via the parameter dataSourceId.

CVE-2016-15004CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-74

A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to injection. The attack can be launched remotely. Upgrading to version 1.6.1.1 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2017-20145CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2022-36444CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in Atos Unify OpenScape SBC 9 and 10 before 10R2.2.1, Atos Unify OpenScape Branch 9 and 10 before version 10R2.1.1, and Atos Unify OpenScape BCF 10 before 10R9.12.1. A remote code execution vulnerability may allow an unauthenticated attacker (with network access to the admin interface) to disrupt system availability or potentially compromise the confidentiality and integrity of the system.

CVE-2022-36450CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-20

Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.

CVE-2020-28435CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.

CVE-2020-28436CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This affects all versions of package google-cloudstorage-commands.

CVE-2020-28438CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js

CVE-2020-28441CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects the package conf-cfg-ini before 1.2.2. If an attacker submits a malicious INI file to an application that parses it with decode, they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-28443CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.

CVE-2020-28445CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-77

This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

CVE-2020-28461CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects the package js-ini before 1.3.0. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-28462CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects all versions of package ion-parser. If an attacker submits a malicious INI file to an application that parses it with parse , they will pollute the prototype on the application. This can be exploited further depending on the context.

CVE-2020-28471CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

This affects the package properties-reader before 2.2.0.

CVE-2020-7677CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.

CVE-2020-7678CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".

CVE-2021-23373CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package set-deep-prop are vulnerable to Prototype Pollution via the main functionality.

CVE-2021-23397CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-1321

All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. Maintainer suggests using @generates/merger instead.

CVE-2021-23451CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-330

The package otp-generator before 3.0.0 are vulnerable to Insecure Randomness due to insecure generation of random one-time passwords, which may allow a brute-force attack.

CVE-2022-2131CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-611

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flags, allowing an attacker to perform a XML external entity injection attack.

CVE-2022-33965CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Multiple Unauthenticated SQL Injection (SQLi) vulnerabilities in Osamaesh WP Visitor Statistics plugin <= 5.7 at WordPress.

CVE-2022-35649CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-94

The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

CVE-2022-24083CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-285

Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.

CVE-2022-35869CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-288

This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from the lack of proper authentication prior to access to functionality. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-17211.

CVE-2022-34907CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.

CVE-2022-34577CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

A vulnerability in adm.cgi of WAVLINK WN535 G3 M35G3R.V5030.180927 allows attackers to execute arbitrary code via a crafted POST request.

CVE-2022-34989CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Fruits Bazar v1.0 was discovered to contain a SQL injection vulnerability via the recover_email parameter at user_password_recover.php.

CVE-2022-36161CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-89

Orange Station 1.0 was discovered to contain a SQL injection vulnerability via the username parameter.

CVE-2022-36412CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

In Zoho ManageEngine SupportCenter Plus before 11023, V3 API requests are vulnerable to authentication bypass. (An API request may, in effect, be executed with the credentials of a user who authenticated in the past.)

CVE-2022-29953CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.

CVE-2022-29958CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-345

JTEKT TOYOPUC PLCs through 2022-04-29 do not ensure data integrity. They utilize the unauthenticated CMPLink/TCP protocol for engineering purposes, including downloading projects and control logic to the PLC. Control logic is downloaded to the PLC on a block-by-block basis with a given memory address and a blob of machine code. The logic that is downloaded to the PLC is not cryptographically authenticated, allowing an attacker to execute arbitrary machine code on the PLC's CPU module in the context of the runtime. In the case of the PC10G-CPU, and likely for other CPU modules of the TOYOPUC family, a processor without MPU or MMU is used and this no memory protection or privilege-separation capabilities are available, giving an attacker full control over the CPU.

CVE-2022-30273CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-327

The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message integrity and offers reduced confidentiality above the block level, as demonstrated by an ECB Penguin attack against any block ciphers.

CVE-2022-31206CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

The Omron SYSMAC Nx product family PLCs (NJ series, NY series, NX series, and PMAC series) through 2022-005-18 lack cryptographic authentication. These PLCs are programmed using the SYMAC Studio engineering software (which compiles IEC 61131-3 conformant POU code to native machine code for execution by the PLC's runtime). The resulting machine code is executed by a runtime, typically controlled by a real-time operating system. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, allowing an attacker to manipulate transmitted object code to the PLC and execute arbitrary machine code on the processor of the PLC's CPU module in the context of the runtime. In the case of at least the NJ series, an RTOS and hardware combination is used that would potentially allow for memory protection and privilege separation and thus limit the impact of code execution. However, it was not confirmed whether these sufficiently segment the runtime from the rest of the RTOS.

CVE-2022-30271CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.

CVE-2022-31207CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-347

The Omron SYSMAC Cx product family PLCs (CS series, CJ series, and CP series) through 2022-05-18 lack cryptographic authentication. They utilize the Omron FINS (9600/TCP) protocol for engineering purposes, including downloading projects and control logic to the PLC. This protocol has authentication flaws as reported in FSCT-2022-0057. Control logic is downloaded to PLC volatile memory using the FINS Program Area Read and Program Area Write commands or to non-volatile memory using other commands from where it can be loaded into volatile memory for execution. The logic that is loaded into and executed from the user program area exists in compiled object code form. Upon execution, these object codes are first passed to a dedicated ASIC that determines whether the object code is to be executed by the ASIC or the microprocessor. In the former case, the object code is interpreted by the ASIC whereas in the latter case the object code is passed to the microprocessor for object code interpretation by a ROM interpreter. In the abnormal case where the object code cannot be handled by either, an abnormal condition is triggered and the PLC is halted. The logic that is downloaded to the PLC does not seem to be cryptographically authenticated, thus allowing an attacker to manipulate transmitted object code to the PLC and either execute arbitrary object code commands on the ASIC or on the microprocessor interpreter.

CVE-2022-30270CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-287

The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts (root, abuilder, acelogin, cappl, ace), all of which come with default credentials. Although the ACE1000 documentation mentions the root, abuilder and acelogin accounts and instructs users to change the default credentials, the cappl and ace accounts remain undocumented and thus are unlikely to have their credentials changed.

CVE-2022-30274CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly, the ACE1000 RTU can route MDLC traffic over Extended Command and Management Protocol (XCMP) and Network Layer (XNL) networks via the MDLC driver. Authentication to the XNL port is protected by TEA in ECB mode using a hardcoded key.

CVE-2022-2310CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-290

An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.

CVE-2022-23100CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).

CVE-2022-24405CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-78

OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.

CVE-2022-36986CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

An issue was discovered in Veritas NetBackup 8.1.x through 8.1.2, 8.2, 8.3.x through 8.3.0.2, 9.x through 9.0.0.1, and 9.1.x through 9.1.0.1 (and related NetBackup products). An attacker with unauthenticated access could remotely execute arbitrary commands on a NetBackup Primary server.

CVE-2022-31627CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-590

In PHP versions 8.1.x below 8.1.8, when fileinfo functions, such as finfo_buffer, due to incorrect patch applied to the third party code from libmagic, incorrect function may be used to free allocated memory, which may lead to heap corruption.

CVE-2022-22683CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2022-27612CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-120

Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Audio Station before 6.5.4-3367 allows remote attackers to execute arbitrary commands via unspecified vectors.

CVE-2021-22640CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-294

An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.

CVE-2021-22644CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-798

Ovarro TBox TWinSoft uses the custom hardcoded user “TWinSoft” with a hardcoded key.

CVE-2021-22646CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE NVD-CWE-noinfo

The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.

CVE-2021-22648CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-732

Ovarro TBox proprietary Modbus file access functions allow attackers to read, alter, or delete the configuration file.

CVE-2021-22650CRITICALnone
CVSS 9.8
EPSS
Priority 0
CWE CWE-22

An attacker may use TWinSoft and a malicious source project file (TPG) to extract files on machine executing Ovarro TWinSoft, which could lead to code execution.

← PreviousPage 439 / 7034Next →