Loading HuntDB...

High-Impact Vulnerabilities

Critical + High Exploit High EPSS

Vulnerabilities that meet all three criteria: Critical/High severity, known exploits, and high probability of exploitation (EPSS ≥ 10%).

CVE-2023-4415 6 months, 2 weeks ago

A vulnerability was found in Ruijie RG-EW1200G 07161417 r483. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/sys/login. The manipulation leads to improper authentication. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-237518 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

HIGH (7.3) EPSS: 92.0% 1 exploit
Ruijie RG-EW1200G Router Back…
CVE-2023-4220 6 months, 2 weeks ago

Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.

HIGH (8.1) EPSS: 93.0% 1 exploit
Chamilo LMS <= 1.11.24 - Remo…
CVE-2023-4634 6 months, 2 weeks ago

The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are processed via Imagick(). This makes it possible for unauthenticated attackers to supply files via FTP that will make directory lists, local file inclusion, and remote code execution possible.

CRITICAL (9.8) EPSS: 92.4% 1 exploit
Media Library Assistant < 3.0…
CVE-2023-4596 6 months, 2 weeks ago

The Forminator plugin for WordPress is vulnerable to arbitrary file uploads due to file type validation occurring after a file has been uploaded to the server in the upload_post_image() function in versions up to, and including, 1.24.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

CRITICAL (9.8) EPSS: 93.5% 1 exploit
WordPress Plugin Forminator 1…
CVE-2023-25157 6 months, 2 weeks ago

GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse.

CRITICAL (9.8) EPSS: 93.8% 1 exploit
GeoServer OGC Filter - SQL In…
CVE-2023-25573 6 months, 2 weeks ago

metersphere is an open source continuous testing platform. In affected versions an improper access control vulnerability exists in `/api/jmeter/download/files`, which allows any user to download any file without authentication. This issue may expose all files available to the running process. This issue has been addressed in version 1.20.20 lts and 2.7.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.

HIGH (8.6) EPSS: 92.0% 1 exploit
Metersphere - Arbitrary File …
CVE-2022-34753 6 months, 2 weeks ago

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)

HIGH (8.8) EPSS: 91.7% 1 exploit
SpaceLogic C-Bus Home Control…
CVE-2022-30525 6 months, 2 weeks ago

A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.

CRITICAL (9.8) EPSS: 94.4% 1 exploit
Zyxel Firewall - OS Command I…
CVE-2022-27593 6 months, 2 weeks ago

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later

CRITICAL (10.0) EPSS: 93.6% 1 exploit
QNAP QTS Photo Station Extern…
CVE-2022-45365 6 months, 2 weeks ago

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aleksandar Urošević Stock Ticker allows Reflected XSS.This issue affects Stock Ticker: from n/a through 3.23.2.

HIGH (7.1) EPSS: 22.4% 1 exploit
Stock Ticker <= 3.23.2 - Cros…
CVE-2022-45362 6 months, 2 weeks ago

Server-Side Request Forgery (SSRF) vulnerability in Paytm Paytm Payment Gateway.This issue affects Paytm Payment Gateway: from n/a through 2.7.0.

HIGH (7.2) EPSS: 16.7% 1 exploit
WordPress Paytm Payment Gatew…
CVE-2022-45808 6 months, 2 weeks ago

SQL Injection vulnerability in LearnPress – WordPress LMS Plugin <= 4.1.7.3.2 versions.

CRITICAL (9.9) EPSS: 74.7% 1 exploit
LearnPress Plugin < 4.2.0 - U…
CVE-2022-29464 6 months, 2 weeks ago

Certain WSO2 products allow unrestricted file upload with resultant remote code execution. The attacker must use a /fileupload endpoint with a Content-Disposition directory traversal sequence to reach a directory under the web root, such as a ../../../../repository/deployment/server/webapps directory. This affects WSO2 API Manager 2.2.0 up to 4.0.0, WSO2 Identity Server 5.2.0 up to 5.11.0, WSO2 Identity Server Analytics 5.4.0, 5.4.1, 5.5.0 and 5.6.0, WSO2 Identity Server as Key Manager 5.3.0 up to 5.11.0, WSO2 Enterprise Integrator 6.2.0 up to 6.6.0, WSO2 Open Banking AM 1.4.0 up to 2.0.0 and WSO2 Open Banking KM 1.4.0, up to 2.0.0.

CRITICAL (9.8) EPSS: 94.4% 1 exploit
WSO2 Management - Arbitrary F…
CVE-2022-0415 6 months, 2 weeks ago

Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.

CRITICAL (9.9) EPSS: 79.3% 1 exploit
Gogs <0.12.6 - Remote Command…
CVE-2022-0660 6 months, 2 weeks ago

Generation of Error Message Containing Sensitive Information in Packagist microweber/microweber prior to 1.2.11.

CRITICAL (9.4) EPSS: 11.2% 1 exploit
Microweber <1.2.11 - Informat…
CVE-2022-0218 6 months, 2 weeks ago

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

HIGH (8.3) EPSS: 80.7% 1 exploit
HTML Email Template Designer …
CVE-2022-0432 6 months, 2 weeks ago

Prototype Pollution in GitHub repository mastodon/mastodon prior to 3.5.0.

HIGH (7.4) EPSS: 30.3% 1 exploit
Mastodon Prototype Pollution …
CVE-2022-0482 6 months, 2 weeks ago

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository alextselegidis/easyappointments prior to 1.4.3.

CRITICAL (9.1) EPSS: 92.0% 1 exploit
Easy!Appointments <1.4.3 - Br…
CVE-2022-0651 6 months, 2 weeks ago

The WP Statistics WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the current_page_type parameter found in the ~/includes/class-wp-statistics-hits.php file which allows attackers without authentication to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 13.1.5.

CRITICAL (9.8) EPSS: 29.4% 1 exploit
WordPress Plugin WP Statistic…
CVE-2022-0281 6 months, 2 weeks ago

Exposure of Sensitive Information to an Unauthorized Actor in Packagist microweber/microweber prior to 1.2.11.

HIGH (7.5) EPSS: 34.2% 1 exploit
Microweber Information Disclo…