7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0139
radareorg/radare2 General
7.1
HIGH
EPSS
0.4%
2022 CWE-416 1 PoC

Use After Free in GitHub repository radareorg/radare2 prior to 5.6.0.

CVE-2022-33926
Wyse Management Suite General
7.1
HIGH
EPSS
0.3%
2022 CWE-284 1 PoC

Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.

CVE-2022-0926
microweber/microweber Web
7.1
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

File upload filter bypass leading to stored XSS in GitHub repository microweber/microweber prior to 1.2.12.

CVE-2022-0580
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-863 1 PoC

Incorrect Authorization in Packagist librenms/librenms prior to 22.2.0.

CVE-2022-21593
HTTP Server Web Database
7.1
HIGH
EPSS
2.3%
2022 1 PoC

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: OHS Config MBeans). Supported versions that are affected are 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HTTP Server accessible data as well as unauthorized update, insert or delete access to

CVE-2022-31250
Tumbleweed General
7.1
HIGH
EPSS
0.1%
2022 CWE-59 1 PoC

A UNIX Symbolic Link (Symlink) Following vulnerability in keylime of openSUSE Tumbleweed allows local attackers to escalate from the keylime user to root. This issue affects: openSUSE Tumbleweed keylime versions prior to 6.4.2-1.1.

CVE-2022-22753
Firefox Windows
7.1
HIGH
EPSS
0.4%
2022 2 PoCs

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-42855
tvOS General
7.1
HIGH
EPSS
0.1%
2022 6 PoCs

A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2. An app may be able to use arbitrary entitlements.

CVE-2022-25760
accesslog Web
7.1
HIGH
EPSS
0.4%
2022 1 PoC

All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible for an attacker to execute arbitrary JavaScript code on the host that this package is being run on.

CVE-2022-0755
salesagility/suitecrm General
7.1
HIGH
EPSS
0.2%
2022 CWE-862 1 PoC

Missing Authorization in GitHub repository salesagility/suitecrm prior to 7.12.5.

CVE-2022-41221
Software Genérico General
7.1
HIGH
EPSS
0.0%
2022 1 PoC

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administration client (Versions 16.2.3, 21.2, and older versions) could upload XML files to the application that it did not sufficiently validate. As a result, attackers could craft XML files that, when processed by the application, would cause a negative security impact such as data exfiltration or localized denial of service against the application instance and system of the user running it.

CVE-2022-2653
plankanban/planka General
7.1
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able to read any file in the system.

CVE-2022-0821
orchardcms/orchardcore Web
7.1
HIGH
EPSS
0.2%
2022 CWE-285 1 PoC

Improper Authorization in GitHub repository orchardcms/orchardcore prior to 1.3.0.

CVE-2022-22788
Zoom Client for Meetings Windows
7.1
HIGH
EPSS
0.6%
2022 1 PoC

The Zoom Opener installer is downloaded by a user from the Launch meeting page, when attempting to join a meeting without having the Zoom Meeting Client installed. The Zoom Opener installer for Zoom Client for Meetings before version 5.10.3 and Zoom Rooms for Conference Room for Windows before version 5.10.3 are susceptible to a DLL injection attack. This vulnerability could be used to run arbitrary code on the victims host.

CVE-2022-4294
Norton Antivirus Windows Eraser Engine Windows
7.1
HIGH
EPSS
0.1%
2022 CWE-269 1 PoC

Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

CVE-2022-22292
Samsung Mobile Devices General
7.1
HIGH
EPSS
0.0%
2022 CWE-280 1 PoC

Unprotected dynamic receiver in Telecom prior to SMR Feb-2022 Release 1 allows untrusted applications to launch arbitrary activity.

CVE-2022-2924
yetiforcecompany/yetiforcecrm Web
7.1
HIGH
EPSS
0.3%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.3.

CVE-2022-42946
Autodesk Maya General
7.1
HIGH
EPSS
0.1%
2022 1 PoC

Parsing a maliciously crafted X_B and PRT file can force Autodesk Maya 2023 and 2022 to read beyond allocated buffer. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.

CVE-2022-2995
cri-o DevOps
7.1
HIGH
EPSS
0.0%
2022 CWE-284 1 PoC

Incorrect handling of the supplementary groups in the CRI-O container engine might lead to sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code in that container.

CVE-2022-0588
librenms/librenms General
7.1
HIGH
EPSS
0.0%
2022 CWE-862 1 PoC

Missing Authorization in Packagist librenms/librenms prior to 22.2.0.