5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-30164
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Kerberos AppContainer Security Feature Bypass Vulnerability

CVE-2022-21999
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
73.9%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability

CVE-2022-30174
Microsoft 365 Apps for Enterprise General
7.8
HIGH
EPSS
2.9%
2022 1 PoC

Microsoft Office Remote Code Execution Vulnerability

CVE-2022-28672
PDF Reader General
7.8
HIGH
EPSS
22.0%
2022 CWE-416 3 PoCs

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16640.

CVE-2022-4510
binwalk General
7.8
HIGH
EPSS
44.1%
2022 CWE-22 4 PoCs

A path traversal vulnerability was identified in ReFirm Labs binwalk from version 2.1.2b through 2.3.3 included. By crafting a malicious PFS filesystem file, an attacker can get binwalk's PFS extractor to extract files at arbitrary locations when binwalk is run in extraction mode (-e option). Remote code execution can be achieved by building a PFS filesystem that, upon extraction, would extract a malicious binwalk module into the folder .config/binwalk/plugins. This vulnerability is associated with program files src/binwalk/plugins/unpfs.py. This issue affects binwalk from 2.1.2b through 2.3

CVE-2022-41322
Software Genérico General
7.8
HIGH
EPSS
1.4%
2022 1 PoC

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

CVE-2022-45988
Software Genérico General
7.8
HIGH
EPSS
1.3%
2022 1 PoC

starsoftcomm CooCare 5.304 allows local attackers to escalate privileges and execute arbitrary commands via a crafted file upload.

CVE-2022-28678
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16805.

CVE-2022-38037
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
3.0%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-3235
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0490.

CVE-2022-3591
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0789.

CVE-2022-32924
macOS General
7.8
HIGH
EPSS
0.3%
2022 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-45099
PowerScale OneFS General
7.8
HIGH
EPSS
0.0%
2022 CWE-261 1 PoC

Dell PowerScale OneFS, versions 8.2.x-9.4.x, contain a weak encoding for a NDMP password. A malicious and privileged local attacker could potentially exploit this vulnerability, leading to a full system compromise

CVE-2022-3296
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-121 1 PoC

Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.

CVE-2022-28683
PDF Reader General
7.8
HIGH
EPSS
2.0%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the deletePages method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16828.

CVE-2022-4292
vim/vim General
7.8
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0882.

CVE-2022-49059
Linux General
7.8
HIGH
EPSS
0.0%
2022 8 PoCs

In the Linux kernel, the following vulnerability has been resolved: nfc: nci: add flush_workqueue to prevent uaf Our detector found a concurrent use-after-free bug when detaching an NCI device. The main reason for this bug is the unexpected scheduling between the used delayed mechanism (timer and workqueue). The race can be demonstrated below: Thread-1 Thread-2 | nci_dev_up() | nci_open_device() | __nci_request(nci_reset_req) |

CVE-2022-41202
SAP 3D Visual Enterprise Viewer General
7.8
HIGH
EPSS
1.8%
2022 CWE-119 2 PoCs

Due to lack of proper memory management, when a victim opens a manipulated Visual Design Stream (.vds, vds.x3d) file received from untrusted sources in SAP 3D Visual Enterprise Viewer - version 9, it is possible that a Remote Code Execution can be triggered when payload forces a stack-based overflow or a re-use of dangling pointer which refers to overwritten space in memory.

CVE-2022-1968
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-416 2 PoCs

Use After Free in GitHub repository vim/vim prior to 8.2.