5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-37208
Software Genérico Web Database
8.8
HIGH
EPSS
1.1%
2022 1 PoC

JFinal CMS 5.1.0 is vulnerable to SQL Injection. These interfaces do not use the same component, nor do they have filters, but each uses its own SQL concatenation method, resulting in SQL injection.

CVE-2022-46074
Software Genérico DevOps Web
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

Helmet Store Showroom 1.0 is vulnerable to Cross Site Request Forgery (CSRF). An unauthenticated user can add an admin account due to missing CSRF protection.

CVE-2022-22744
Firefox ESR Windows
8.8
HIGH
EPSS
0.4%
2022 1 PoC

The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVE-2022-3852
VR Calendar Web Windows
8.8
HIGH
EPSS
0.4%
2022 CWE-352 1 PoC

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-46552
Software Genérico General
8.8
HIGH
EPSS
18.7%
2022 4 PoCs

D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

CVE-2022-48585
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-22620
🔥 KEV Safari (v and ) General
8.8
HIGH
EPSS
4.0%
2022 2 PoCs

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVE-2022-45942
Software Genérico Web
8.8
HIGH
EPSS
3.9%
2022 1 PoC

A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

CVE-2022-36926
Zoom Rooms for macOS General
8.8
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-45562
Software Genérico General
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.

CVE-2022-22629
Safari Windows
8.8
HIGH
EPSS
21.7%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-41080
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
93.8%
2022 1 PoC

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2022-3199
Chrome General
8.8
HIGH
EPSS
0.8%
2022 1 PoC

Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-1000
prasathmani/tinyfilemanager General
8.8
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

CVE-2022-42070
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2022-48597
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-31877
Software Genérico General
8.8
HIGH
EPSS
0.0%
2022 1 PoC

An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

CVE-2022-32886
iOS General
8.8
HIGH
EPSS
0.9%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-24402
TETRA Standard General
8.8
HIGH
EPSS
0.4%
2022 CWE-334 1 PoC

The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks.