5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-38473
Thunderbird General
8.8
HIGH
EPSS
0.4%
2022 1 PoC

A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVE-2022-3221
ikus060/rdiffweb Web
8.8
HIGH
EPSS
0.2%
2022 CWE-352 1 PoC

Cross-Site Request Forgery (CSRF) in GitHub repository ikus060/rdiffweb prior to 2.4.3.

CVE-2022-35870
Ignition General
8.8
HIGH
EPSS
19.4%
2022 CWE-502 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within com.inductiveautomation.metro.impl. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-17265.

CVE-2022-1339
pimcore/pimcore Web Database
8.8
HIGH
EPSS
0.0%
2022 CWE-89 1 PoC

SQL injection in ElementController.php in GitHub repository pimcore/pimcore prior to 10.3.5. This vulnerability is capable of steal the data

CVE-2022-47542
Software Genérico Database
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

Red Gate SQL Monitor 11.0.14 through 12.1.46 has Incorrect Access Control, exploitable remotely for Escalation of Privileges.

CVE-2022-46699
tvOS General
8.8
HIGH
EPSS
0.5%
2022 5 PoCs

A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-40983
Qt Web
8.8
HIGH
EPSS
0.8%
2022 CWE-190 2 PoCs

An integer overflow vulnerability exists in the QML QtScript Reflect API of Qt Project Qt 6.3.2. A specially-crafted javascript code can trigger an integer overflow during memory allocation, which can lead to arbitrary code execution. Target application would need to access a malicious web page to trigger this vulnerability.

CVE-2022-32774
Foxit Reader Web
8.8
HIGH
EPSS
0.5%
2022 CWE-416 1 PoC

A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely deleting objects associated with pages, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.

CVE-2022-35841
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
26.2%
2022 1 PoC

Windows Enterprise App Management Service Remote Code Execution Vulnerability

CVE-2022-48591
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the vendor_state parameter of the “vendor print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-34269
Software Genérico Web
8.8
HIGH
EPSS
3.3%
2022 1 PoC

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.

CVE-2022-40298
Software Genérico Windows
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Crestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found in the AirMedia Windows Application, version 4.3.1.39. A low privileged user can initiate a repair of the system and gain a SYSTEM level shell.

CVE-2022-35196
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 1 PoC

TestLink v1.9.20 was discovered to contain a Cross-Site Request Forgery (CSRF) via /lib/plan/planView.php.

CVE-2022-23919
LinkHub Mesh Wifi General
8.8
HIGH
EPSS
0.5%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the confsrv set_mf_rule functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.This vulnerability leverages the name field within the protobuf message to cause a buffer overflow.

CVE-2022-42719
Software Genérico General
8.8
HIGH
EPSS
0.6%
2022 2 PoCs

A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.

CVE-2022-1329
Elementor Website Builder Web Windows ⚡ nuclei
8.8
HIGH
EPSS
93.4%
2022 CWE-862 8 PoCs

The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.

CVE-2022-38841
Software Genérico General
8.8
HIGH
EPSS
16.6%
2022 1 PoC

Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.

CVE-2022-29557
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 1 PoC

LexisNexis Firco Compliance Link 3.7 allows CSRF.

CVE-2022-4262
🔥 KEV Chrome General
8.8
HIGH
EPSS
8.6%
2022 3 PoCs

Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-48199
Software Genérico Windows
8.8
HIGH
EPSS
0.6%
2022 1 PoC

SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitrary binary execution and can be modified by any user. The resulting binary execution will occur in the context of any user running NetWorx. If an attacker modifies the Notifications function to execute a malicious binary, the binary will be executed by every user running NetWorx on that system.