5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-1256
McAfee Agent for Windows Windows
7.8
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges through manipulation of symbolic links.

CVE-2022-1968
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-416 2 PoCs

Use After Free in GitHub repository vim/vim prior to 8.2.

CVE-2022-21491
VM VirtualBox Database Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.34. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows systems only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I

CVE-2022-26532
USG/ZyWALL series firmware Networking
7.8
HIGH
EPSS
1.7%
2022 CWE-88 1 PoC

A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware ver

CVE-2022-2182
vim/vim General
7.8
HIGH
EPSS
0.7%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-28669
PDF Reader General
7.8
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16420.

CVE-2022-25972
libhdf5 Networking
7.8
HIGH
EPSS
0.1%
2022 CWE-787 1 PoC

An out-of-bounds write vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-3591
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0789.

CVE-2022-41034
Visual Studio Code General
7.8
HIGH
EPSS
63.2%
2022 1 PoC

Visual Studio Code Remote Code Execution Vulnerability

CVE-2022-22990
My Cloud Web Cloud
7.8
HIGH
EPSS
1.7%
2022 CWE-287 1 PoC

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.

CVE-2022-32168
notepad-plus-plus General
7.8
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVE-2022-37991
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-24411
PowerScale OneFS Networking
7.8
HIGH
EPSS
0.1%
2022 CWE-378 1 PoC

Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to circumvent PowerScale Compliance Mode guarantees.

CVE-2022-42260
vGPU software (guest driver) - Linux, NVIDIA Cloud Gaming (guest driver) Cloud
7.8
HIGH
EPSS
0.2%
2022 CWE-281 1 PoC

NVIDIA vGPU Display Driver for Linux guest contains a vulnerability in a D-Bus configuration file, where an unauthorized user in the guest VM can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-26061
libhdf5 Networking
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-30426
Software Genérico General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

There is a stack buffer overflow vulnerability, which could lead to arbitrary code execution in UEFI DXE driver on some Acer products. An attack could exploit this vulnerability to escalate privilege from ring 3 to ring 0, and hijack control flow during UEFI DXE execution. This affects Altos T110 F3 firmware version <= P13 (latest) and AP130 F2 firmware version <= P04 (latest) and Aspire 1600X firmware version <= P11.A3L (latest) and Aspire 1602M firmware version <= P11.A3L (latest) and Aspire 7600U firmware version <= P11.A4 (latest) and Aspire MC605 firmware version <= P11.A4L (latest) and A

CVE-2022-38928
Software Genérico General
7.8
HIGH
EPSS
0.2%
2022 1 PoC

XPDF 4.04 is vulnerable to Null Pointer Dereference in FoFiType1C.cc:2393.

CVE-2022-37706
Software Genérico General
7.8
HIGH
EPSS
56.2%
2022 9 PoCs

enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.