94322 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-3852
VR Calendar Web Windows
8.8
HIGH
EPSS
0.4%
2022 CWE-352 1 PoC

The VR Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.3.3. This is due to missing or incorrect nonce validation on several functions. This makes it possible for unauthenticated attackers to delete, and modify calendars as well as the plugin settings, via forged request granted they can trick a site administrator into performing an action such as clicking on a link.

CVE-2022-46552
Software Genérico General
8.8
HIGH
EPSS
18.7%
2022 4 PoCs

D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan(0)_dhcps_staticlist parameter. This vulnerability is exploited via a crafted POST request.

CVE-2022-48585
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “admin brand portal” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-22620
🔥 KEV Safari (v and ) General
8.8
HIGH
EPSS
4.0%
2022 2 PoCs

A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

CVE-2022-45942
Software Genérico Web
8.8
HIGH
EPSS
3.9%
2022 1 PoC

A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

CVE-2022-36926
Zoom Rooms for macOS General
8.8
HIGH
EPSS
0.2%
2022 CWE-78 1 PoC

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-45562
Software Genérico General
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Insecure permissions in Telos Alliance Omnia MPX Node v1.0.0 to v1.4.9 allow attackers to manipulate and access system settings with backdoor account low privilege, this can lead to change hardware settings and execute arbitrary commands in vulnerable system functions that is requires high privilege to access.

CVE-2022-22629
Safari Windows
8.8
HIGH
EPSS
21.7%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-41080
🔥 KEV Microsoft Exchange Server 2016 Cumulative Update 23 Windows
8.8
HIGH
EPSS
93.8%
2022 1 PoC

Microsoft Exchange Server Elevation of Privilege Vulnerability

CVE-2022-3199
Chrome General
8.8
HIGH
EPSS
0.8%
2022 1 PoC

Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2022-1000
prasathmani/tinyfilemanager General
8.8
HIGH
EPSS
0.4%
2022 CWE-22 1 PoC

Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.

CVE-2022-42070
Software Genérico Web
8.8
HIGH
EPSS
0.1%
2022 2 PoCs

Online Birth Certificate Management System version 1.0 is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2022-48597
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-31877
Software Genérico General
8.8
HIGH
EPSS
0.0%
2022 1 PoC

An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

CVE-2022-32886
iOS General
8.8
HIGH
EPSS
0.9%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-24402
TETRA Standard General
8.8
HIGH
EPSS
0.4%
2022 CWE-334 1 PoC

The TETRA TEA1 keystream generator implements a key register initialization function that compresses the 80-bit key to only 32 bits for usage during the keystream generation phase, which is insufficient to safeguard against exhaustive search attacks.

CVE-2022-48601
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-47042
Software Genérico Web
8.8
HIGH
EPSS
0.3%
2022 1 PoC

MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.

CVE-2022-43654
CAX30S Web Networking
8.8
HIGH
EPSS
2.7%
2022 CWE-78 1 PoC

NETGEAR CAX30S SSO Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR CAX30S routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the token parameter provided to the sso.php endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-18227.