7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-41114
Windows 10 Version 21H1 Windows
7.0
HIGH
EPSS
0.6%
2022 1 PoC

Windows Bind Filter Driver Elevation of Privilege Vulnerability

CVE-2022-41667
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-41666
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.0%
2022 CWE-347 1 PoC

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-1340
yetiforcecompany/yetiforcecrm Web
7.0
HIGH
EPSS
0.2%
2022 CWE-79 1 PoC

Cross-site Scripting (XSS) - Stored in GitHub repository yetiforcecompany/yetiforcecrm prior to 6.4.0.

CVE-2022-42864
macOS General
7.0
HIGH
EPSS
4.0%
2022 8 PoCs

A race condition was addressed with improved state handling. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.

CVE-2022-41670
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-22 1 PoC

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-2564
automattic/mongoose General
7.0
HIGH
EPSS
2.9%
2022 CWE-1321 1 PoC

Prototype Pollution in GitHub repository automattic/mongoose prior to 6.4.6.

CVE-2022-2820
namelessmc/nameless General
7.0
HIGH
EPSS
0.3%
2022 CWE-384 1 PoC

Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.

CVE-2022-3133
jgraph/drawio General
7.0
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

OS Command Injection in GitHub repository jgraph/drawio prior to 20.3.0.

CVE-2022-41669
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.0%
2022 CWE-347 1 PoC

A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-21881
Windows 10 Version 1809 Windows
7.0
HIGH
EPSS
6.7%
2022 2 PoCs

Windows Kernel Elevation of Privilege Vulnerability

CVE-2022-41668
EcoStruxure Operator Terminal Expert General
7.0
HIGH
EPSS
0.1%
2022 CWE-704 1 PoC

A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-24834
redis Database
7.0
HIGH
EPSS
46.1%
2022 CWE-122 2 PoCs

Redis is an in-memory database that persists on disk. A specially crafted Lua script executing in Redis can trigger a heap overflow in the cjson library, and result with heap corruption and potentially remote code execution. The problem exists in all versions of Redis with Lua scripting support, starting from 2.6, and affects only authenticated and authorized users. The problem is fixed in versions 7.0.12, 6.2.13, and 6.0.20.

CVE-2022-37318
Software Genérico Web
7.0
HIGH
EPSS
0.6%
2022 1 PoC

Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.

CVE-2022-41741
NGINX Web
7.0
HIGH
EPSS
0.8%
2022 CWE-787 1 PoC

NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger proces

CVE-2022-41671
EcoStruxure Operator Terminal Expert Database
7.0
HIGH
EPSS
0.2%
2022 CWE-89 1 PoC

A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

CVE-2022-42267
NVIDIA GPU Display Driver for Windows Windows
7.0
HIGH
EPSS
0.1%
2022 CWE-345 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.

CVE-2022-41211
SAP 3D Visual Enterprise Author General
7.0
HIGH
EPSS
0.2%
2022 CWE-787 1 PoC

Due to lack of proper memory management, when a victim opens manipulated file received from untrusted sources in SAP 3D Visual Enterprise Author and SAP 3D Visual Enterprise Viewer, Arbitrary Code Execution can be triggered when payload forces:Re-use of dangling pointer which refers to overwritten space in memory. The accessed memory must be filled with code to execute the attack. Therefore, repeated success is unlikely.Stack-based buffer overflow. Since the memory overwritten is random, based on access rights of the memory, repeated success is not assured.

CVE-2022-46361
OneWireless General
6.9
MEDIUM
EPSS
0.0%
2022 CWE-77 1 PoC

An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted commands. This issue affects OneWireless all versions up to 322.1 and fixed in version 322.2.