CVE-Datenbank
Archiv bekannter Schwachstellen (CVEs) mit CVSS-Wert, Schweregrad, betroffenen Produkten und Herstellern. Nach Jahr und Schweregrad filterbar.
- CVE-2022-41049Mittel5.4
Windows Mark of the Web Security Feature Bypass Vulnerability
- CVE-2022-31199Kritisch9.8
Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
- CVE-2022-3723Hoch8.8
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2022-42827Hoch7.8
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
- CVE-2022-38181Hoch8.8
The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.
- CVE-2016-20017Kritisch9.8
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016 through 2022.
- CVE-2022-21587Kritisch9.8
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2022-40684Kritisch9.8
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
- CVE-2022-41033Hoch7.8
Windows COM+ Event System Service Elevation of Privilege Vulnerability
- CVE-2022-38028Hoch7.8
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-41082Hoch8.0
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-41040Hoch8.8
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2022-20775Hoch7.8
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
- CVE-2022-3075Kritisch9.6
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2022-3038Hoch8.8
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-2856Mittel6.5
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
- CVE-2022-41352Kritisch9.8
Ein Problem wurde in Zimbra Collaboration (ZCS) 8.8.15 und 9.0 entdeckt. Ein Angreifer kann über amavis durch eine cpio-Lücke (Extraktion nach /opt/zimbra/jetty/webapps/zimbra/public) beliebige Dateien hochladen, was zu falschem Zugriff auf beliebige andere Benutzerkonten führen kann. Zimbra empfiehlt pax anstelle von cpio. Außerdem gehört pax zu den Voraussetzungen von Zimbra unter Ubuntu; pax ist jedoch nach RHEL 6 (oder CentOS 6) nicht mehr Teil einer Standard-Red-Hat-Installation. Sobald pax installiert ist, bevorzugt amavis es automatisch gegenüber cpio.
- CVE-2022-3236Kritisch9.8
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
- CVE-2022-39197Mittel6.1
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
- CVE-2022-32917Hoch7.8
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
This product uses the NVD API but is not endorsed or certified by the NVD.