40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-30710
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2021-39149
xstream General
8.5
HIGH
EPSS
0.6%
2021 CWE-434 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVE-2021-39147
xstream General
8.5
HIGH
EPSS
0.7%
2021 CWE-434 3 PoCs

XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose.

CVE-2022-27826
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in SemSuspendDialogInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-2636
hestiacp/hestiacp General
8.5
HIGH
EPSS
0.4%
2022 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.

CVE-2020-37064
EPSON EasyMP Network Projection General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges.

CVE-2021-47825
Acer Updater Service General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during service startup.

CVE-2021-47896
PDFCOMPLETE Corporate Edition General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

PDF Complete Corporate Edition 4.1.45 contains an unquoted service path vulnerability in the pdfcDispatcher service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in the service binary location to inject malicious executables that will be run with elevated LocalSystem privileges.

CVE-2024-13206
Antivirus General
8.5
HIGH
EPSS
0.0%
2024 CWE-276 1 PoC

A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2020-37021
Bandwidth Monitor General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

10-Strike Bandwidth Monitor 3.9 contains an unquoted service path vulnerability in multiple services that allows local attackers to escalate privileges. Attackers can place a malicious executable in specific file path locations to achieve privilege escalation to SYSTEM during service startup.

CVE-2021-47810
WibuKey Runtime General
8.5
HIGH
EPSS
0.0%
2021 CWE-428 1 PoC

WibuKey Runtime 6.51 contains an unquoted service path vulnerability in the WkSvW32.exe service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\PROGRAM FILES (X86)\WIBUKEY\SERVER\WkSvW32.exe' to inject malicious executables and escalate privileges.

CVE-2020-37100
Sync Breeze Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.

CVE-2020-37016
BarcodeOCR General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

BarcodeOCR 19.3.6 contains an unquoted service path vulnerability that allows local attackers to execute code with elevated privileges during system startup. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will run with LocalSystem privileges.

CVE-2020-37098
Disk Sorter Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2020-37020
SonarQube General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

SonarQube 8.3.1 contains an unquoted service path vulnerability that allows local attackers to gain SYSTEM privileges by exploiting the service executable path. Attackers can replace the wrapper.exe in the service path with a malicious executable to execute code with highest system privileges during service restart.

CVE-2022-50900
Wondershare Dr.Fone General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path to insert malicious code that will be executed with LocalSystem permissions during service startup.

CVE-2022-30756
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Implicit Intent hijacking vulnerability in Finder prior to SMR Jul-2022 Release 1 allow allows attackers to launch certain activities with privilege of Finder.

CVE-2022-50913
TCQ General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code with elevated system privileges. Attackers can insert a malicious executable in the service path to gain elevated access during service restart or system reboot.

CVE-2023-54331
Outline General
8.5
HIGH
EPSS
0.0%
2023 CWE-428 1 PoC

Outline 1.6.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted service path in the OutlineService executable to inject malicious code that will be executed with LocalSystem permissions.

CVE-2020-37102
Web Companion General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.