7835 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-32168
notepad-plus-plus General
7.8
HIGH
EPSS
0.1%
2022 CWE-427 1 PoC

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

CVE-2022-24367
PDF Reader General
7.8
HIGH
EPSS
0.7%
2022 CWE-416 1 PoC

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15877.

CVE-2022-26532
USG/ZyWALL series firmware Networking
7.8
HIGH
EPSS
1.7%
2022 CWE-88 1 PoC

A argument injection vulnerability in the 'packet-trace' CLI command of Zyxel USG/ZyWALL series firmware versions 4.09 through 4.71, USG FLEX series firmware versions 4.50 through 5.21, ATP series firmware versions 4.32 through 5.21, VPN series firmware versions 4.30 through 5.21, NSG series firmware versions 1.00 through 1.33 Patch 4, NXC2500 firmware version 6.10(AAIG.3) and earlier versions, NAP203 firmware version 6.25(ABFA.7) and earlier versions, NWA50AX firmware version 6.25(ABYW.5) and earlier versions, WAC500 firmware version 6.30(ABVS.2) and earlier versions, and WAX510D firmware ver

CVE-2022-24411
PowerScale OneFS Networking
7.8
HIGH
EPSS
0.1%
2022 CWE-378 1 PoC

Dell PowerScale OneFS 8.2.2 and above contain an elevation of privilege vulnerability. A local attacker with ISI_PRIV_LOGIN_SSH and/or ISI_PRIV_LOGIN_CONSOLE could potentially exploit this vulnerability, leading to elevation of privilege. This could potentially allow users to circumvent PowerScale Compliance Mode guarantees.

CVE-2022-2817
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0213.

CVE-2022-26582
Software Genérico General
7.8
HIGH
EPSS
0.7%
2022 1 PoC

PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. The attacker must have shell access to the device in order to exploit this vulnerability.

CVE-2022-45115
Ichitaro General
7.8
HIGH
EPSS
0.4%
2022 CWE-122 2 PoCs

A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2022-37326
Software Genérico DevOps Web Windows
7.8
HIGH
EPSS
0.1%
2022 1 PoC

Docker Desktop for Windows before 4.6.0 allows attackers to delete (or create) any file through the dockerBackendV2 windowscontainers/start API by controlling the pidfile field inside the DaemonJSON field in the WindowsContainerStartRequest class. This can indirectly lead to privilege escalation.

CVE-2022-42274
NVIDIA DGX servers General
7.8
HIGH
EPSS
0.2%
2022 CWE-120 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow and cause a denial of service or gain code execution.

CVE-2022-30164
Windows 10 Version 1809 DevOps Windows
7.8
HIGH
EPSS
0.9%
2022 1 PoC

Kerberos AppContainer Security Feature Bypass Vulnerability

CVE-2022-40847
Software Genérico Networking
7.8
HIGH
EPSS
1.4%
2022 1 PoC

In Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This vulnerability allows attackers to run arbitrary commands on the server via the hostname parameter.

CVE-2022-2816
vim/vim General
7.8
HIGH
EPSS
0.0%
2022 CWE-125 1 PoC

Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.

CVE-2022-3235
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0490.

CVE-2022-3155
Thunderbird General
7.8
HIGH
EPSS
0.0%
2022 1 PoC

When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received file was an application and the user attempted to open it, then the application was started immediately without asking the user to confirm. This vulnerability affects Thunderbird < 102.3.

CVE-2022-3256
vim/vim General
7.8
HIGH
EPSS
0.1%
2022 CWE-416 1 PoC

Use After Free in GitHub repository vim/vim prior to 9.0.0530.

CVE-2022-22990
My Cloud Web Cloud
7.8
HIGH
EPSS
1.7%
2022 CWE-287 1 PoC

A limited authentication bypass vulnerability was discovered that could allow an attacker to achieve remote code execution and escalate privileges on the My Cloud devices. Addressed this vulnerability by changing access token validation logic and rewriting rule logic on PHP scripts.

CVE-2022-28637
HPE Integrated Lights-Out 5 (iLO 5) General
7.8
HIGH
EPSS
0.1%
2022 1 PoC

A local Denial of Service (DoS) and local arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability were discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses these security vulnerabilities.

CVE-2022-42261
vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) Cloud
7.8
HIGH
EPSS
0.1%
2022 CWE-120 1 PoC

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

CVE-2022-1381
vim/vim General
7.8
HIGH
EPSS
0.9%
2022 CWE-122 2 PoCs

global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution