5104 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22960
🔥 KEV VMware Workspace ONE Access, Identity Manager and vRealize Automation General
7.8
HIGH
EPSS
72.7%
2022 3 PoCs

VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'.

CVE-2022-43701
Arm Compiler 5 (AC5), Arm Compiler for Embedded 6 (AC6), Fast Models (FM), Arm Compiler for Embedded FuSA (ACEF), Arm Development Studio (ADS), Arm Forge (AF), Arm Mobile Studio (AMS), DS-5 Development Studio, Fast Models (FM), GNU Toolchain (GT), Keil MDK (KMDK), Mbed Studio (MS) General
7.8
HIGH
EPSS
0.1%
2022 CWE-276 1 PoC

When the installation directory does not have sufficiently restrictive file permissions, an attacker can modify files in the installation directory to cause execution of malicious code.

CVE-2022-27677
Ryzen™ Master General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user.

CVE-2022-2129
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-787 1 PoC

Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.

CVE-2022-25973
mc-kill-port General
7.8
HIGH
EPSS
0.3%
2022 1 PoC

All versions of package mc-kill-port are vulnerable to Arbitrary Command Execution via the kill function, due to missing sanitization of the port argument.

CVE-2022-37234
Software Genérico Networking
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Netgear Nighthawk AC1900 Smart WiFi Dual Band Gigabit Router R7000-V1.0.11.134_10.2.119 is vulnerable to Buffer Overflow via the wl binary in firmware. There is a stack overflow vulnerability caused by strncpy.

CVE-2022-34711
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
0.7%
2022 1 PoC

Windows Defender Credential Guard Elevation of Privilege Vulnerability

CVE-2022-23804
KiCad General
7.8
HIGH
EPSS
0.7%
2022 CWE-121 2 PoCs

A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2286
vim/vim General
7.8
HIGH
EPSS
0.2%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.

CVE-2022-0729
vim/vim General
7.8
HIGH
EPSS
0.5%
2022 CWE-823 2 PoCs

Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

CVE-2022-44830
Software Genérico General
7.8
HIGH
EPSS
6.5%
2022 1 PoC

Sourcecodester Event Registration App v1.0 was discovered to contain multiple CSV injection vulnerabilities via the First Name, Contact and Remarks fields. These vulnerabilities allow attackers to execute arbitrary code via a crafted excel file.

CVE-2022-42850
iOS and iPadOS General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 16.2 and iPadOS 16.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-0847
🔥 KEV kernel General
7.8
HIGH
EPSS
82.3%
2022 CWE-665 102 PoCs

A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.

CVE-2022-1154
vim/vim General
7.8
HIGH
EPSS
1.6%
2022 CWE-416 2 PoCs

Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

CVE-2022-45115
Ichitaro General
7.8
HIGH
EPSS
0.4%
2022 CWE-122 2 PoCs

A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-2845
vim/vim General
7.8
HIGH
EPSS
0.5%
2022 CWE-1284 1 PoC

Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.

CVE-2022-0166
McAfee Agent for Windows Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

CVE-2022-31254
SUSE Linux Enterprise Server for SAP 15 General
7.8
HIGH
EPSS
0.0%
2022 CWE-276 1 PoC

A Incorrect Default Permissions vulnerability in rmt-server-regsharing service of SUSE Linux Enterprise Server for SAP 15, SUSE Linux Enterprise Server for SAP 15-SP1, SUSE Manager Server 4.1; openSUSE Leap 15.3, openSUSE Leap 15.4 allows local attackers with access to the _rmt user to escalate to root. This issue affects: SUSE Linux Enterprise Server for SAP 15 rmt-server versions prior to 2.10. SUSE Linux Enterprise Server for SAP 15-SP1 rmt-server versions prior to 2.10. SUSE Manager Server 4.1 rmt-server versions prior to 2.10. openSUSE Leap 15.3 rmt-server versions prior to 2.10. openSUSE

CVE-2022-43638
PDF Reader General
7.8
HIGH
EPSS
1.7%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18627.

CVE-2022-22718
🔥 KEV Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
7.7%
2022 1 PoC

Windows Print Spooler Elevation of Privilege Vulnerability