3441 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2022-0868
medialize/uri.js General
8.0
HIGH
EPSS
0.3%
2022 CWE-601 1 PoC

Open Redirect in GitHub repository medialize/uri.js prior to 1.19.10.

CVE-2022-21934
Metasys ADS/ADX/OAS server General
8.0
HIGH
EPSS
0.3%
2022 CWE-620 1 PoC

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.

CVE-2022-1410
CMDB General
8.0
HIGH
EPSS
1.2%
2022 CWE-78 1 PoC

OS Command Injection vulnerability in the db_optimize component of Device42 Asset Management Appliance allows an authenticated attacker to execute remote code on the device. This issue affects: Device42 CMDB version 18.01.00 and prior versions.

CVE-2022-1544
luyadev/yii-helpers General
8.0
HIGH
EPSS
0.4%
2022 CWE-1236 1 PoC

Formula Injection/CSV Injection due to Improper Neutralization of Formula Elements in CSV File in GitHub repository luyadev/yii-helpers prior to 1.2.1. Successful exploitation can lead to impacts such as client-sided command injection, code execution, or remote ex-filtration of contained confidential data.

CVE-2022-2287
vim/vim General
8.0
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVE-2022-24931
Samsung Mobile Devices General
7.9
HIGH
EPSS
0.0%
2022 CWE-269 1 PoC

Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022 Release allows unauthorized attackers to execute arbitrary activity without a proper permission

CVE-2022-1823
McAfee Consumer Product Removal Tool General
7.9
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code, through not correctly checking the integrity of the configuration file.

CVE-2022-1714
radareorg/radare2 General
7.9
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository radareorg/radare2 prior to 5.7.0. The bug causes the program reads data past the end of the intented buffer. Typically, this can allow attackers to read sensitive information from other memory locations or cause a crash.

CVE-2022-1824
McAfee Consumer Product Removal Tool General
7.9
HIGH
EPSS
0.2%
2022 CWE-427 1 PoC

An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.

CVE-2022-3037
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0322.

CVE-2022-3699
HardwareScanPlugin General
7.8
HIGH
EPSS
85.1%
2022 CWE-787 2 PoCs

A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.

CVE-2022-43751
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges.

CVE-2022-1381
vim/vim General
7.8
HIGH
EPSS
0.9%
2022 CWE-122 2 PoCs

global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

CVE-2022-31244
Software Genérico General
7.8
HIGH
EPSS
0.0%
2022 2 PoCs

Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.

CVE-2022-41034
Visual Studio Code General
7.8
HIGH
EPSS
63.2%
2022 1 PoC

Visual Studio Code Remote Code Execution Vulnerability

CVE-2022-2206
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVE-2022-35259
Ivanti Endpoint Manager General
7.8
HIGH
EPSS
0.6%
2022 CWE-91 1 PoC

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

CVE-2022-20489
Android General
7.8
HIGH
EPSS
0.0%
2022 2 PoCs

In many functions of AutomaticZenRule.java, there is a possible failure to persist permissions settings due to resource exhaustion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-242703460

CVE-2022-32908
iOS General
7.8
HIGH
EPSS
0.1%
2022 2 PoCs

A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. A user may be able to elevate privileges.

CVE-2022-1537
gruntjs/grunt General
7.8
HIGH
EPSS
0.2%
2022 CWE-367 1 PoC

file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can create a symlink to the GruntJS user's .bashrc file or replace /etc/shadow file if the GruntJS user is root.