5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3256
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

CVE-2022-40847
Software Genérico Networking
7.8
HIGH
EPSS
1.4%
2022 1 PoC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.

CVE-2022-37706
Software Genérico General
7.8
HIGH
EPSS
56.2%
2022 9 PoCs

enlightenment_sys in Enlightenment before 0.25.4 allows local users to gain privileges because it is setuid root, and the system library function mishandles pathnames that begin with a /dev/.. substring.

CVE-2022-45770
Software Genérico Windows
7.8
HIGH
EPSS
0.7%
2022 3 PoCs

Improper input validation in adgnetworkwfpdrv.sys in Adguard For Windows x86 through 7.11 allows local privilege escalation.

CVE-2022-22993
My Cloud Cloud
7.8
HIGH
EPSS
0.1%
2022 CWE-918 1 PoC

A limited SSRF vulnerability was discovered on Western Digital My Cloud devices that could allow an attacker to impersonate a server and reach any page on the server by bypassing access controls. The vulnerability was addressed by creating a whitelist for valid parameters.

CVE-2022-1851
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-125 2 PoCs

Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.

CVE-2022-46693
iCloud for Windows Cloud Windows
7.8
HIGH
EPSS
0.2%
2022 4 PoCs

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in tvOS 16.2, iCloud for Windows 14.1, macOS Ventura 13.1, iOS 16.2 and iPadOS 16.2, watchOS 9.2. Processing a maliciously crafted file may lead to arbitrary code execution.

CVE-2022-30166
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.6%
2022 1 PoC

Local Security Authority Subsystem Service Elevation of Privilege Vulnerability

CVE-2022-25365
Software Genérico DevOps Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Docker Desktop before 4.5.1 on Windows allows attackers to move arbitrary files. NOTE: this issue exists because of an incomplete fix for CVE-2022-23774.

CVE-2022-2288
vim/vim General
7.8
HIGH
EPSS
0.5%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.

CVE-2022-24356
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader Foxit reader 11.0.1.0719 macOS. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the OnMouseExit method. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14848.

CVE-2022-2289
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.

CVE-2022-2951
HyperView Player General
7.8
HIGH
EPSS
0.2%
2022 CWE-129 1 PoC

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption.

CVE-2022-35259
Ivanti Endpoint Manager General
7.8
HIGH
EPSS
0.6%
2022 CWE-91 1 PoC

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privileges.

CVE-2022-21974
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.8%
2022 1 PoC

Roaming Security Rights Management Services Remote Code Execution Vulnerability

CVE-2022-24971
PDF Reader General
7.8
HIGH
EPSS
1.0%
2022 CWE-125 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JPEG2000 images. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15812.

CVE-2022-46697
macOS General
7.8
HIGH
EPSS
0.2%
2022 1 PoC

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-3016
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0286.