7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-0768
rudloff/alltube General
8.6
HIGH
EPSS
0.8%
2022 CWE-918 1 PoC

Server-Side Request Forgery (SSRF) in GitHub repository rudloff/alltube prior to 3.0.2.

CVE-2022-4813
usememos/memos General
8.6
HIGH
EPSS
0.3%
2022 CWE-1220 1 PoC

Insufficient Granularity of Access Control in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-4799
usememos/memos General
8.6
HIGH
EPSS
0.2%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.1.

CVE-2022-1055
Kernel General
8.6
HIGH
EPSS
0.0%
2022 CWE-416 2 PoCs

A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5

CVE-2022-4686
usememos/memos General
8.6
HIGH
EPSS
0.1%
2022 CWE-639 1 PoC

Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.

CVE-2022-34671
NVIDIA GPU Display Driver for Windows Windows
8.5
HIGH
EPSS
0.5%
2022 CWE-787 4 PoCs

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user-mode layer, where an unprivileged user can cause an out-of-bounds write, which may lead to code execution, information disclosure, and denial of service.

CVE-2022-30713
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-30710
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.1%
2022 CWE-20 1 PoC

Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-50928
Bluetooth Application BlueSoleilCS Windows
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

BlueSoleilCS 5.4.277 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path in 'C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleilCS.exe' to inject malicious executables and escalate privileges.

CVE-2022-50921
WOW21 General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

WOW21 5.0.1.9 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path to inject malicious executables that will be launched with LocalSystem permissions during service startup.

CVE-2022-27830
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in SemBlurInfo prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-21430
Communications Billing and Revenue Management Database
8.5
HIGH
EPSS
0.8%
2022 1 PoC

Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Connection Manager). Supported versions that are affected are 12.0.0.4 and 12.0.0.5. Difficult to exploit vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management. While the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of O

CVE-2022-50913
TCQ General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

ITeC ITeCProteccioAppServer contains an unquoted service path vulnerability that allows local attackers to execute code with elevated system privileges. Attackers can insert a malicious executable in the service path to gain elevated access during service restart or system reboot.

CVE-2022-50918
VIVE Runtime Service General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

VIVE Runtime Service 1.0.0.4 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific system directories to gain LocalSystem access during service startup.

CVE-2022-50927
Cyclades Serial Console Server General
8.5
HIGH
EPSS
0.0%
2022 CWE-266 1 PoC

Cyclades Serial Console Server 3.3.0 contains a local privilege escalation vulnerability due to overly permissive sudo privileges for the admin user and admin group. Attackers can exploit the default user configuration to gain root access by manipulating system binaries and leveraging unrestricted sudo permissions.

CVE-2022-27829
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in VerifyCredentialResponse prior to SMR Apr-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-33704
Samsung Mobile Devices General
8.5
HIGH
EPSS
0.0%
2022 CWE-20 1 PoC

Improper validation vulnerability in ucmRetParcelable of KnoxSDK prior to SMR Jul-2022 Release 1 allows attackers to launch certain activities.

CVE-2022-24715
icingaweb2 Networking
8.5
HIGH
EPSS
72.5%
2022 CWE-22 5 PoCs

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.

CVE-2022-22772
TIBCO Managed File Transfer Platform Server for UNIX General
8.5
HIGH
EPSS
1.5%
2022 1 PoC

The cfsend, cfrecv, and CyberResp components of TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX and TIBCO Managed File Transfer Platform Server for z/Linux contain a difficult to exploit Remote Code Execution (RCE) vulnerability that allows a low privileged attacker with network access to execute arbitrary code on the affected system. Affected releases are TIBCO Software Inc.'s TIBCO Managed File Transfer Platform Server for UNIX: versions 8.1.0 and below and TIBCO Managed File Transfer Platform Server for z/Linux: versions 8.1.0 and below.

CVE-2022-50938
CONTPAQ AdminPAQ General
8.5
HIGH
EPSS
0.0%
2022 CWE-428 1 PoC

CONTPAQi AdminPAQ 14.0.0 contains an unquoted service path vulnerability in the AppKeyLicenseServer service running with LocalSystem privileges. Attackers can exploit the unquoted path to inject malicious code in the service binary path, potentially executing arbitrary code with elevated system privileges during service startup.