7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-21510
Database - Enterprise Edition Database
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Oracle Database - Enterprise Edition Sharding executes to compromise Oracle Database - Enterprise Edition Sharding. While the vulnerability is in Oracle Database - Enterprise Edition Sharding, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result

CVE-2022-48595
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-22764
Firefox General
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-36927
Zoom Rooms for macOS General
8.8
HIGH
EPSS
0.0%
2022 CWE-367 1 PoC

Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-36930
Zoom Rooms for Windows Windows
8.8
HIGH
EPSS
0.2%
2022 CWE-427 1 PoC

Zoom Rooms for Windows installers before version 5.13.0 contain a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability in an attack chain to escalate their privileges to the SYSTEM user.

CVE-2022-0664
gravitl/netmaker General
8.8
HIGH
EPSS
0.3%
2022 CWE-321 1 PoC

Use of Hard-coded Cryptographic Key in Go github.com/gravitl/netmaker prior to 0.8.5,0.9.4,0.10.0,0.10.1.

CVE-2022-37718
Software Genérico General
8.8
HIGH
EPSS
14.9%
2022 1 PoC

The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via unspecified vectors

CVE-2022-36924
Zoom Rooms Installer for Windows Windows
8.8
HIGH
EPSS
0.0%
2022 CWE-427 1 PoC

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

CVE-2022-46499
Software Genérico Web Database
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

CVE-2022-45922
Software Genérico General
8.8
HIGH
EPSS
2.1%
2022 3 PoCs

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The request handler for ll.KeepAliveSession sets a valid AdminPwd cookie even when the Web Admin password was not entered. This allows access to endpoints, which require a valid AdminPwd cookie, without knowing the password.

CVE-2022-4096
appsmithorg/appsmith General
8.8
HIGH
EPSS
9.0%
2022 CWE-918 2 PoCs

Server-Side Request Forgery (SSRF) in GitHub repository appsmithorg/appsmith prior to 1.8.2.

CVE-2022-3751
owncast/owncast Database
8.8
HIGH
EPSS
0.5%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.

CVE-2022-23064
snipe-it General
8.8
HIGH
EPSS
0.4%
2022 CWE-74 1 PoC

In Snipe-IT, versions v3.0-alpha to v5.3.7 are vulnerable to Host Header Injection. By sending a specially crafted host header in the reset password request, it is possible to send password reset links to users which once clicked lead to an attacker controlled server and thus leading to password reset token leak. This leads to account take over.

CVE-2022-46443
Software Genérico Database ⚡ nuclei
8.8
HIGH
EPSS
83.4%
2022 2 PoCs

mesinkasir Bangresto 1.0 is vulnberable to SQL Injection via the itemqty%5B%5D parameter.

CVE-2022-3989
Motors Web Windows
8.8
HIGH
EPSS
0.8%
2022 1 PoC

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

CVE-2022-41828
Software Genérico Cloud
8.8
HIGH
EPSS
9.6%
2022 1 PoC

In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.

CVE-2022-23614
Twig Web
8.8
HIGH
EPSS
27.8%
2022 CWE-74 2 PoCs

Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.

CVE-2022-46435
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

An issue in the firmware update process of TP-Link TL-WR941ND V2/V3 up to 3.13.9 and TL-WR941ND V4 up to 3.12.8 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.

CVE-2022-50805
Senayan Library Management System Database
8.8
HIGH
EPSS
0.1%
2022 CWE-89 1 PoC

Senayan Library Management System 9.0.0 contains a SQL injection vulnerability in the 'class' parameter that allows attackers to inject malicious SQL queries. Attackers can exploit the vulnerability by submitting crafted payloads to manipulate database queries and potentially extract sensitive information.

CVE-2022-44638
Software Genérico General
8.8
HIGH
EPSS
0.4%
2022 2 PoCs

In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.