1481 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2022-3852
VR Calendar Web Windows
8.8
HIGH
EPSS
0.4%
2022 CWE-352 1 PoC

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-3769
OWM Weather Web Database Windows
8.8
HIGH
EPSS
0.7%
2022 2 PoCs

The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as contributor

CVE-2022-3359
Shortcodes and extra features for Phlox theme Web Windows
8.8
HIGH
EPSS
0.8%
2022 1 PoC

The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.

CVE-2022-41080
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
93.8%
2022 1 PoC

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2022-40298
Software Genérico Windows
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.

CVE-2022-3805
Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress Web Windows ⚡ nuclei
8.6
HIGH
EPSS
8.5%
2022 CWE-639 0 PoCs

The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various functions used to update the plugin settings in versions up to, and including, 2.5.6. Unauthenticated users can use an easily available nonce, obtained from pages edited by the plugin, to update the MailChimp API key, global styles, 404 page settings, and enabled elements.

CVE-2022-50935
FLAME II MODEM USB Windows
8.5
HIGH
EPSS
0.1%
2022 CWE-428 1 PoC

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

CVE-2022-50928
Bluetooth Application BlueSoleilCS Windows
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe' to inject malicious executables and escalate privileges.

CVE-2022-34671
NVIDIA GPU Display Driver for Windows Windows
8.5
HIGH
EPSS
0.5%
2022 CWE-787 4 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.

CVE-2022-28182
NVIDIA GPU Display Driver Windows
8.5
HIGH
EPSS
1.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVE-2022-28181
NVIDIA GPU Display Driver Windows
8.5
HIGH
EPSS
1.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVE-2022-50920
Sandboxie Plus Windows
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Sandboxie-Plus 5.50.2 contains an unquoted service path vulnerability in the SbieSvc Windows service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2022-0218
WP HTML Mail Web Windows ⚡ nuclei
8.3
HIGH
EPSS
62.4%
2022 CWE-862 0 PoCs

The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.

CVE-2022-37397
Yugabyte DB Windows
8.3
HIGH
EPSS
0.5%
2022 CWE-287 1 PoC

An issue was discovered in the YugabyteDB 2.6.1 when using LDAP-based authentication in YCQL with Microsoft’s Active Directory. When anonymous or unauthenticated LDAP binding is enabled, it allows bypass of authentication with an empty password.

CVE-2022-4896
Control de Ciber Windows
8.2
HIGH
EPSS
1.4%
2022 CWE-400 1 PoC

Cyber Control, in its 1.650 version, is affected by a vulnerability in the generation on the server of pop-up windows with the messages "PNTMEDIDAS", "PEDIR", "HAYDISCOA" or "SPOOLER". A complete denial of service can be achieved by sending multiple requests simultaneously on a core.

CVE-2022-39424
VM VirtualBox Database Windows
8.1
HIGH
EPSS
6.8%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVE-2022-3763
Booster for WooCommerce Web Windows
8.1
HIGH
EPSS
0.2%
2022 1 PoC

The Booster for WooCommerce WordPress plugin before 5.6.7, Booster Plus for WooCommerce WordPress plugin before 5.6.5, Booster Elite for WooCommerce WordPress plugin before 1.1.7 do not have CSRF check in place when deleting files uploaded at the checkout, allowing attackers to make a logged in shop manager or admin delete them via a CSRF attack

CVE-2022-23270
Windows 10 Version 1809 Windows
8.1
HIGH
EPSS
48.4%
2022 1 PoC

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability

CVE-2022-21936
Software Genérico Windows
8.1
HIGH
EPSS
0.2%
2022 1 PoC

On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.