5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-2285
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-190 1 PoC

Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.

CVE-2022-3605
WP CSV Exporter Web Windows
7.8
HIGH
EPSS
0.3%
2022 1 PoC

The WP CSV Exporter WordPress plugin before 1.3.7 does not properly escape the fields when exporting data as CSV, leading to a CSV injection vulnerability.

CVE-2022-2946
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0246.

CVE-2022-41992
PowerISO General
7.8
HIGH
EPSS
0.1%
2022 CWE-787 1 PoC

A memory corruption vulnerability exists in the VHD File Format parsing CXSPARSE record functionality of PowerISO PowerISO 8.3. A specially-crafted file can lead to an out-of-bounds write. A victim needs to open a malicious file to trigger this vulnerability.

CVE-2022-34705
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Windows Defender Credential Guard Elevation of Privilege Vulnerability

CVE-2022-28637
HPE Integrated Lights-Out 5 (iLO 5) General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A local Denial of Service (DoS) and local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

CVE-2022-2175
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-126 1 PoC

Buffer Over-read in GitHub repository vim/vim prior to 8.2.

CVE-2022-2889
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0225.

CVE-2022-2344
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.

CVE-2022-24366
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15853.

CVE-2022-4956
Advanced Installer General
7.8
HIGH
EPSS
0.2%
2022 CWE-427 1 PoC

A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version 19.7.1 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-240903.

CVE-2022-37991
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
1.2%
2022 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-41057
Windows 10 Version 1809 Web Windows
7.8
HIGH
EPSS
1.1%
2022 2 PoCs

Windows HTTP.sys Elevation of Privilege Vulnerability

CVE-2022-23947
KiCad General
7.8
HIGH
EPSS
0.8%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-43649
PDF Reader General
7.8
HIGH
EPSS
1.5%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.2.12465. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19478.

CVE-2022-1898
vim/vim General
7.8
HIGH
EPSS
0.3%
2022 CWE-416 2 PoCs

Use After Free in GitHub repository vim/vim prior to 8.2.

CVE-2022-4292
vim/vim General
7.8
HIGH
EPSS
0.3%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0882.

CVE-2022-2207
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

CVE-2022-2849
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-122 1 PoC

Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.

CVE-2022-30190
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
93.6%
2022 75 PoCs

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights. Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.