92 vulnerabilidades · 🔥 KEV Orden: CVSS EPSS Año ID
CVE-2022-40799
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
53.9%
2022 1 PoC

Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device.

CVE-2022-3038
🔥 KEV Chrome General
8.8
HIGH
EPSS
36.0%
2022 1 PoC

Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVE-2022-43939
🔥 KEV Pentaho Business Analytics Server General ⚡ nuclei
8.6
HIGH
EPSS
93.3%
2022 CWE-647 2 PoCs

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented.

CVE-2022-0185
🔥 KEV kernel Web
8.4
HIGH
EPSS
2.3%
2022 CWE-190 10 PoCs

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

CVE-2022-37969
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
11.6%
2022 3 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-32917
🔥 KEV iOS General
7.8
HIGH
EPSS
0.6%
2022 4 PoCs

The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

CVE-2022-0847
🔥 KEV kernel General
7.8
HIGH
EPSS
82.3%
2022 CWE-665 102 PoCs

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CVE-2022-41073
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-30190
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
93.6%
2022 75 PoCs

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.

CVE-2022-22960
🔥 KEV VMware Workspace ONE Access, Identity Manager and vRealize Automation General
7.8
HIGH
EPSS
72.7%
2022 3 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-22706
🔥 KEV Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 2 PoCs

Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.

CVE-2022-32894
🔥 KEV iOS and iPadOS General
7.8
HIGH
EPSS
0.2%
2022 2 PoCs

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.

CVE-2022-22718
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.7%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-20775
🔥 KEV Cisco Catalyst SD-WAN Web Networking Cloud
7.8
HIGH
EPSS
0.4%
2022 CWE-25 1 PoC

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/cen

CVE-2022-21999
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
73.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-27924
🔥 KEV Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
91.2%
2022 0 PoCs

Zimbra Collaboration (aka ZCS) 8.8.15 and 9.0 allows an unauthenticated attacker to inject arbitrary memcache commands into a targeted instance. These memcache commands becomes unescaped, causing an overwrite of arbitrary cached entries.

CVE-2022-30333
🔥 KEV Software Genérico Networking
7.5
HIGH
EPSS
92.8%
2022 8 PoCs

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.