9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2018-0798
🔥 KEV Equation Editor General
8.8
HIGH
EPSS
94.1%
2018 1 PoC

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Memory Corruption Vulnerability".

CVE-2011-10007
File::Find::Rule General
8.8
HIGH
EPSS
0.3%
2011 CWE-78 1 PoC

File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted filename. A file handle is opened with the 2 argument form of `open()` allowing an attacker controlled filename to provide the MODE parameter to `open()`, turning the filename into a command to be executed. Example: $ mkdir /tmp/poc; echo > "/tmp/poc/|id" $ perl -MFile::Find::Rule \     -E 'File::Find::Rule->grep("foo")->in("/tmp/poc")' uid=1000(user) gid=1000(user) groups=1000(user),100(users)

CVE-2022-45781
Software Genérico General
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Buffer Overflow vulnerability in Tenda AX1803 v1.0.0.1_2994 and earlier allows attackers to run arbitrary code via /goform/SetOnlineDevName.

CVE-2022-20607
Android General
8.8
HIGH
EPSS
4.8%
2022 1 PoC

In the Pixel cellular firmware, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with LTE authentication needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238914868References: N/A

CVE-2022-28640
HPE Integrated Lights-Out 5 (iLO 5) General
8.8
HIGH
EPSS
0.4%
2022 1 PoC

A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.

CVE-2022-30129
Visual Studio Code General
8.8
HIGH
EPSS
38.9%
2022 1 PoC

Visual Studio Code Remote Code Execution Vulnerability

CVE-2022-4505
openemr/openemr General
8.8
HIGH
EPSS
0.5%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository openemr/openemr prior to 7.0.0.2.

CVE-2022-45927
Software Genérico General
8.8
HIGH
EPSS
1.2%
2022 3 PoCs

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Java application server can be used to bypass the authentication of the QDS endpoints of the Content Server. These endpoints can be used to create objects and execute arbitrary code.

CVE-2022-28639
HPE Integrated Lights-Out 5 (iLO 5) General
8.8
HIGH
EPSS
0.1%
2022 1 PoC

A remote potential adjacent denial of service (DoS) and potential adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

CVE-2022-45893
Software Genérico General
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Planet eStream before 6.72.10.07 allows a low-privileged user to gain access to administrative and high-privileged user accounts by changing the value of the ON cookie. A brute-force attack can calculate a value that provides permanent access.

CVE-2022-23067
ToolJet General
8.8
HIGH
EPSS
0.4%
2022 CWE-200 1 PoC

ToolJet versions v0.5.0 to v1.2.2 are vulnerable to token leakage via Referer header that leads to account takeover . If the user opens the invite link/signup link and then clicks on any external links within the page, it leaks the password set token/signup token in the referer header. Using these tokens the attacker can access the user’s account.

CVE-2022-24401
TETRA Standard General
8.8
HIGH
EPSS
0.2%
2022 CWE-323 1 PoC

Adversary-induced keystream re-use on TETRA air-interface encrypted traffic using any TEA keystream generator. IV generation is based upon several TDMA frame counters, which are frequently broadcast by the infrastructure in an unauthenticated manner. An active adversary can manipulate the view of these counters in a mobile station, provoking keystream re-use. By sending crafted messages to the MS and analyzing MS responses, keystream for arbitrary frames can be recovered.

CVE-2022-34155
OAuth Single Sign On – SSO (OAuth Client) General
8.8
HIGH
EPSS
0.2%
2022 CWE-287 1 PoC

Improper Authentication vulnerability in miniOrange OAuth Single Sign On – SSO (OAuth Client) plugin allows Authentication Bypass.This issue affects OAuth Single Sign On – SSO (OAuth Client): from n/a through 6.23.3.

CVE-2022-34446
PowerPath Management Appliance General
8.8
HIGH
EPSS
0.3%
2022 CWE-285 1 PoC

PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass vulnerability. An authenticated remote user with limited privileges (e.g., of role Monitoring) can exploit this issue and gain access to sensitive information, and modify the configuration.

CVE-2022-1316
zerotier/zerotierone General
8.8
HIGH
EPSS
0.1%
2022 CWE-732 1 PoC

Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation

CVE-2022-40469
Software Genérico General
8.8
HIGH
EPSS
4.9%
2022 1 PoC

iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.

CVE-2022-26485
🔥 KEV Firefox General
8.8
HIGH
EPSS
7.2%
2022 1 PoC

Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.

CVE-2022-46700
tvOS General
8.8
HIGH
EPSS
0.5%
2022 6 PoCs

A memory corruption issue was addressed with improved input validation. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-2853
Chrome General
8.8
HIGH
EPSS
1.4%
2022 1 PoC

Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.