Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2022-29303
Known exploited
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CVSS Score
9.8
EPSS Score
0.98
Published
2022-05-12
CVE-2022-30525
Known exploited
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 700 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 50(W) firmware versions 5.10 through 5.21 Patch 1, USG20(W)-VPN firmware versions 5.10 through 5.21 Patch 1, ATP series firmware versions 5.10 through 5.21 Patch 1, VPN series firmware versions 4.60 through 5.21 Patch 1, which could allow an attacker to modify specific files and then execute some OS commands on a vulnerable device.
CVSS Score
9.8
EPSS Score
0.999
Published
2022-05-12
CVE-2022-26923
Known exploited
Active Directory Domain Services Elevation of Privilege Vulnerability
CVSS Score
8.8
EPSS Score
0.828
Published
2022-05-10
CVE-2022-26925
Known exploited
Windows LSA Spoofing Vulnerability
CVSS Score
8.1
EPSS Score
0.105
Published
2022-05-10
CVE-2022-30333
Known exploited
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
CVSS Score
7.5
EPSS Score
0.99
Published
2022-05-09
CVE-2022-1388
Known exploited
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
CVSS Score
9.8
EPSS Score
1.0
Published
2022-05-05
CVE-2022-24706
Known exploited
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations.
CVSS Score
9.8
EPSS Score
0.925
Published
2022-04-26
CVE-2022-29499
Known exploited
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
CVSS Score
9.8
EPSS Score
0.554
Published
2022-04-26
CVE-2022-27924
Known exploited
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.
CVSS Score
7.5
EPSS Score
0.854
Published
2022-04-21
CVE-2022-27925
Known exploited
Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it. An authenticated user with administrator rights has the ability to upload arbitrary files to the system, leading to directory traversal.
CVSS Score
7.2
EPSS Score
0.986
Published
2022-04-21


Contact Us

Shodan ® - All rights reserved