7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-46394
Software Genérico General
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Valhall r39p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.

CVE-2022-45928
Software Genérico General
8.8
HIGH
EPSS
2.8%
2022 3 PoCs

A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands.

CVE-2022-45600
Software Genérico Networking
8.8
HIGH
EPSS
41.8%
2022 1 PoC

Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges by leveraging an existing web portal login.

CVE-2022-44789
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2022 1 PoC

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

CVE-2022-47875
Software Genérico Web
8.8
HIGH
EPSS
23.0%
2022 1 PoC

A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

CVE-2022-48604
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-26927
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
28.1%
2022 2 PoCs

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2022-4237
Welcart e-Commerce Web Windows
8.8
HIGH
EPSS
1.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable gadget chain is present on the blog

CVE-2022-34756
Easergy P5 Web
8.8
HIGH
EPSS
1.9%
2022 CWE-120 1 PoC

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)

CVE-2022-42221
Software Genérico General
8.8
HIGH
EPSS
2.6%
2022 1 PoC

Netgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability.

CVE-2022-34468
Firefox Web
8.8
HIGH
EPSS
0.5%
2022 1 PoC

An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVE-2022-2067
francoisjacquet/rosariosis Database
8.8
HIGH
EPSS
0.8%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.

CVE-2022-24724
cmark-gfm General
8.8
HIGH
EPSS
4.2%
2022 CWE-190 1 PoC

cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16_MAX columns. The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution depending on how and where `cmark-gfm` is used. If `cmark-gfm` is used for rendering remote user controlled markdown, this vulnerability may lead to Remote Code Execution (RCE) in

CVE-2022-38065
OpenStack DevOps
8.8
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVE-2022-45923
Software Genérico General
8.8
HIGH
EPSS
3.1%
2022 3 PoCs

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value chosen by the attacker.

CVE-2022-27641
R6700v3 Networking
8.8
HIGH
EPSS
0.3%
2022 CWE-190 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15806.

CVE-2022-44384
Software Genérico Web
8.8
HIGH
EPSS
48.7%
2022 1 PoC

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-21442
GoldenGate Database
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Vulnerability in Oracle GoldenGate (component: OGG Core Library). The supported version that is affected is Prior to 23.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:

CVE-2022-40282
Software Genérico General
8.8
HIGH
EPSS
0.8%
2022 2 PoCs

The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.

CVE-2022-33012
Software Genérico General
8.8
HIGH
EPSS
1.6%
2022 1 PoC

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.