2639 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-22772
TIBCO Managed File Transfer Platform Server for UNIX General
8.5
HIGH
EPSS
1.5%
2022 1 PoC

The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX and TIBCO Managed File Transfer Platform Server for z/Linux contain a difficult to exploit Remote Code Execution (RCE) vulnerability that allows a low privileged attacker with network access to execute arbitrary code on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX: versions 8.1.0 and below and TIBCO Managed File Transfer Platform Server for z/Linux: versions 8.1.0 and below.

CVE-2022-50938
CONTPAQ AdminPAQ General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.

CVE-2022-50935
FLAME II MODEM USB Windows
8.5
HIGH
EPSS
0.1%
2022 CWE-428 1 PoC

Flame II HSPA USB Modem contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Internet Telcel\ApplicationController.exe' to execute arbitrary code with elevated system privileges.

CVE-2022-50693
Splashtop General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and escalate privileges.

CVE-2022-27829
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-50900
Wondershare Dr.Fone General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Wondershare Dr.Fone 12.0.18 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the misconfigured service path to insert malicious code that will be executed with LocalSystem permissions during service startup.

CVE-2022-23626
blog Web
8.5
HIGH
EPSS
4.3%
2022 CWE-20 1 PoC

m1k1o/blog is a lightweight self-hosted facebook-styled PHP blog. Errors from functions `imagecreatefrom*` and `image*` have not been checked properly. Although PHP issued warnings and the upload function returned `false`, the original file (that could contain a malicious payload) was kept on the disk. Users are advised to upgrade as soon as possible. There are no known workarounds for this issue.

CVE-2022-41268
Business Planning and Consolidation General
8.5
HIGH
EPSS
0.3%
2022 CWE-269 1 PoC

In some SAP standard roles in SAP Business Planning and Consolidation - versions - SAP_BW 750, 751, 752, 753, 754, 755, 756, 757, DWCORE 200, 300, CPMBPC 810, a transaction code reserved for the customer is used. By implementing such transaction code, a malicious user may execute unauthorized transaction functionality. Under specific circumstances, a successful attack could enable an adversary to escalate their privileges to be able to read, change or delete system data.

CVE-2022-28181
NVIDIA GPU Display Driver Windows
8.5
HIGH
EPSS
1.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where an unprivileged regular user on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVE-2022-21430
Communications Billing and Revenue Management Database
8.5
HIGH
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of O

CVE-2022-34671
NVIDIA GPU Display Driver for Windows Windows
8.5
HIGH
EPSS
0.5%
2022 CWE-787 4 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.

CVE-2022-50928
Bluetooth Application BlueSoleilCS Windows
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe' to inject malicious executables and escalate privileges.

CVE-2022-50789
Impact/Pulse/First Web
8.5
HIGH
EPSS
1.6%
2022 CWE-78 1 PoC

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vulnerable dns.php script, which triggers command execution and then deletes the file.

CVE-2022-50923
Cobian Backup General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Cobian Backup 0.9 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CobianReflectorService to inject malicious code that will execute with LocalSystem permissions during service startup.

CVE-2022-29090
Wyse Management Suite General
8.5
HIGH
EPSS
0.2%
2022 CWE-317 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target device and perform unauthorized actions.

CVE-2022-50927
Cyclades Serial Console Server General
8.5
HIGH
EPSS
0.0%
2022 CWE-266 1 PoC

Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.

CVE-2022-28182
NVIDIA GPU Display Driver Windows
8.5
HIGH
EPSS
1.1%
2022 CWE-787 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the DirectX11 user mode driver (nvwgf2um/x.dll), where an unauthorized attacker on the network can cause an out-of-bounds write through a specially crafted shader, which may lead to code execution to cause denial of service, escalation of privileges, information disclosure, and data tampering. The scope of the impact may extend to other components.

CVE-2022-50924
Private Internet Access General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

CVE-2022-50929
Connectify Hotspot General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

Connectify Hotspot 2018 contains an unquoted service path vulnerability in its ConnectifyService executable that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files (x86)\Connectify\ConnectifyService.exe' to inject malicious executables and escalate privileges.

CVE-2022-50902
Wondershare FamiSafe General
8.5
HIGH
EPSS
0.0%
2022 CWE-91 1 PoC

Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Wondershare\FamiSafe\ to inject malicious code that would run with LocalSystem permissions during service startup.