5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-45639
Software Genérico General
7.8
HIGH
EPSS
1.0%
2022 3 PoCs

OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.

CVE-2022-3178
gpac/gpac General
7.8
HIGH
EPSS
0.2%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository gpac/gpac prior to 2.1.0-DEV.

CVE-2022-20441
Android General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

In navigateUpTo of Task.java, there is a possible way to launch an unexported intent handler due to a logic error in the code. This could lead to local escalation of privilege if the targeted app has an intent trampoline, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-238605611

CVE-2022-35768
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.8%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-34707
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.5%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-41395
Software Genérico Networking
7.8
HIGH
EPSS
1.6%
2022 2 PoCs

Tenda AC1200 Router Model W15Ev2 V15.11.0.10(1576) was discovered to contain a command injection vulnerability via the dmzHost parameter in the setDMZ function.

CVE-2022-3134
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0389.

CVE-2022-37381
PDF Reader General
7.8
HIGH
EPSS
2.0%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the AFSpecial_KeystrokeEx method. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17110.

CVE-2022-32911
iOS General
7.8
HIGH
EPSS
0.2%
2022 2 PoCs

The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-42849
tvOS Web
7.8
HIGH
EPSS
0.1%
2022 3 PoCs

An access issue existed with privileged API calls. This issue was addressed with additional restrictions. This issue is fixed in iOS 16.2 and iPadOS 16.2, tvOS 16.2, watchOS 9.2. A user may be able to elevate privileges.

CVE-2022-48622
Software Genérico Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

In GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk in io-ani.c) when parsing chunks in a crafted .ani file. A crafted file could allow an attacker to overwrite heap metadata, leading to a denial of service or code execution attack. This occurs in gdk_pixbuf_set_option() in gdk-pixbuf.c.

CVE-2022-2182
vim/vim General
7.8
HIGH
EPSS
0.7%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-3604
Contact Form Entries Web Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

The Contact Form Entries WordPress plugin before 1.3.0 does not validate data when its output in a CSV file, which could lead to CSV injection.

CVE-2022-37969
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
11.6%
2022 3 PoCs

Windows Common Log File System Driver Elevation of Privilege Vulnerability

CVE-2022-28638
HPE Integrated Lights-Out 5 (iLO 5) General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

An isolated local disclosure of information and potential isolated local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

CVE-2022-1927
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-126 2 PoCs

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVE-2022-37385
PDF Reader General
7.8
HIGH
EPSS
2.0%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17301.