7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-42098
Software Genérico Web Database
8.8
HIGH
EPSS
1.6%
2022 2 PoCs

KLiK SocialMediaWebsite version v1.0.1 is vulnerable to SQL Injection via the profile.php.

CVE-2022-48601
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-22756
Firefox General
8.8
HIGH
EPSS
0.3%
2022 2 PoCs

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVE-2022-23103
LinkHub Mesh Wifi General
8.8
HIGH
EPSS
0.5%
2022 CWE-121 1 PoC

A stack-based buffer overflow vulnerability exists in the confsrv confctl_set_app_language functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to stack-based buffer overflow. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-31877
Software Genérico General
8.8
HIGH
EPSS
0.0%
2022 1 PoC

An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.

CVE-2022-22740
Firefox ESR General
8.8
HIGH
EPSS
0.3%
2022 1 PoC

Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVE-2022-22629
Safari Windows
8.8
HIGH
EPSS
21.7%
2022 2 PoCs

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.3, Safari 15.4, watchOS 8.5, iTunes 12.12.3 for Windows, iOS 15.4 and iPadOS 15.4, tvOS 15.4. Processing maliciously crafted web content may lead to arbitrary code execution.

CVE-2022-3751
owncast/owncast Database
8.8
HIGH
EPSS
0.5%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository owncast/owncast prior to 0.0.13.

CVE-2022-36924
Zoom Rooms Installer for Windows Windows
8.8
HIGH
EPSS
0.0%
2022 CWE-427 1 PoC

The Zoom Rooms Installer for Windows prior to 5.12.6 contains a local privilege escalation vulnerability. A local low-privileged user could exploit this vulnerability during the install process to escalate their privileges to the SYSTEM user.

CVE-2022-0511
Firefox General
8.8
HIGH
EPSS
0.4%
2022 1 PoC

Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97.

CVE-2022-46499
Software Genérico Web Database
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.

CVE-2022-28751
Zoom Client for Meetings for MacOS General
8.8
HIGH
EPSS
0.0%
2022 CWE-347 1 PoC

The Zoom Client for Meetings for MacOS (Standard and for IT Admin) before version 5.11.3 contains a vulnerability in the package signature validation during the update process. A local low-privileged user could exploit this vulnerability to escalate their privileges to root.

CVE-2022-0520
radareorg/radare2 General
8.8
HIGH
EPSS
0.2%
2022 CWE-416 1 PoC

Use After Free in NPM radare2.js prior to 5.6.2.

CVE-2022-40469
Software Genérico General
8.8
HIGH
EPSS
4.9%
2022 1 PoC

iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.

CVE-2022-1578
My wpdb Web Database Windows
8.8
HIGH
EPSS
0.2%
2022 1 PoC

The My wpdb WordPress plugin before 2.5 is missing CSRF check when running SQL queries, which could allow attacker to make a logged in admin run arbitrary SQL query via a CSRF attack

CVE-2022-0721
microweber/microweber General
8.8
HIGH
EPSS
0.4%
2022 CWE-215 1 PoC

Insertion of Sensitive Information Into Debugging Code in GitHub repository microweber/microweber prior to 1.3.

CVE-2022-35841
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
26.2%
2022 1 PoC

Windows Enterprise App Management Service Remote Code Execution Vulnerability

CVE-2022-1397
alextselegidis/easyappointments Web
8.8
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

API Privilege Escalation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. Full system takeover.

CVE-2022-44256
Software Genérico General
8.8
HIGH
EPSS
0.7%
2022 1 PoC

TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.

CVE-2022-23642
sourcegraph Web Networking
8.8
HIGH
EPSS
85.3%
2022 CWE-94 3 PoCs

Sourcegraph is a code search and navigation engine. Sourcegraph prior to version 3.37 is vulnerable to remote code execution in the `gitserver` service. The service acts as a git exec proxy, and fails to properly restrict calling `git config`. This allows an attacker to set the git `core.sshCommand` option, which sets git to use the specified command instead of ssh when they need to connect to a remote system. Exploitation of this vulnerability depends on how Sourcegraph is deployed. An attacker able to make HTTP requests to internal services like gitserver is able to exploit it. This issue is