9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-42161
Software Genérico General
8.8
HIGH
EPSS
9.2%
2022 1 PoC

D-Link COVR 1200,1202,1203 v1.08 was discovered to contain a command injection vulnerability via the /SetTriggerWPS/PIN parameter at function SetTriggerWPS.

CVE-2022-2921
notrinos/notrinoserp General
8.8
HIGH
EPSS
0.5%
2022 CWE-359 1 PoC

Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository notrinos/notrinoserp prior to v0.7. This results in privilege escalation to a system administrator account. An attacker can gain access to protected functionality such as create/update companies, install/update languages, install/activate extensions, install/activate themes and other permissive actions.

CVE-2022-42198
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 1 PoC

In Simple Exam Reviewer Management System v1.0 the User List function suffers from insecure file upload.

CVE-2022-3196
Chrome General
8.8
HIGH
EPSS
0.6%
2022 1 PoC

Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)

CVE-2022-42716
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r29p0 through r40P0.

CVE-2022-46552
Software Genérico General
8.8
HIGH
EPSS
18.7%
2022 4 PoCs

D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

CVE-2022-22620
🔥 KEV Safari (v and ) General
8.8
HIGH
EPSS
4.0%
2022 2 PoCs

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVE-2022-36926
Zoom Rooms for macOS General
8.8
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-45562
Software Genérico General
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.

CVE-2022-3199
Chrome General
8.8
HIGH
EPSS
0.8%
2022 1 PoC

Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-1000
prasathmani/tinyfilemanager General
8.8
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

CVE-2022-31877
Software Genérico General
8.8
HIGH
EPSS
0.0%
2022 1 PoC

An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

CVE-2022-32886
iOS General
8.8
HIGH
EPSS
0.9%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-24402
TETRA Standard General
8.8
HIGH
EPSS
0.4%
2022 CWE-334 1 PoC

The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks.

CVE-2022-48580
SL 1 General
8.8
HIGH
EPSS
0.5%
2022 CWE-78 1 PoC

A command injection vulnerability exists in the ARP ping device tool feature of the ScienceLogic SL1 that takes unsanitized user controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVE-2022-21154
Leadtools General
8.8
HIGH
EPSS
0.2%
2022 CWE-190 1 PoC

An integer overflow vulnerability exists in the fltSaveCMP functionality of Leadtools 22. A specially-crafted BMP file can lead to an integer overflow, that in turn causes a buffer overflow. An attacker can provide a malicious BMP file to trigger this vulnerability.

CVE-2022-41264
BASIS General
8.8
HIGH
EPSS
0.8%
2022 CWE-94 1 PoC

Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters provided by the attacker. On successful exploitation the attacker can have full control of the system to which the class belongs, causing a high impact on the integrity of the application.

CVE-2022-48584
SL 1 General
8.8
HIGH
EPSS
0.5%
2022 CWE-78 1 PoC

A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.

CVE-2022-34753
SpaceLogic C-Bus Home Controller General ⚡ nuclei
8.8
HIGH
EPSS
93.8%
2022 CWE-78 2 PoCs

A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote root exploit when the command is compromised. Affected Products: SpaceLogic C-Bus Home Controller (5200WHC2), formerly known as C-Bus Wiser Homer Controller MK2 (V1.31.460 and prior)