Base de données CVE
Archive des vulnérabilités connues (CVE) avec score CVSS, gravité, produits et éditeurs concernés. Filtrez par année et par sévérité.
- CVE-2022-21587Critique9.8
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
- CVE-2022-40684Critique9.8
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
- CVE-2022-41033Élevée7.8
Windows COM+ Event System Service Elevation of Privilege Vulnerability
- CVE-2022-38028Élevée7.8
Windows Print Spooler Elevation of Privilege Vulnerability
- CVE-2022-41082Élevée8.0
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-41040Élevée8.8
Microsoft Exchange Server Elevation of Privilege Vulnerability
- CVE-2022-20775Élevée7.8
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
- CVE-2022-3075Critique9.6
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2022-3038Élevée8.8
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-2856Moyenne6.5
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
- CVE-2022-41352Critique9.8
Un problème a été découvert dans Zimbra Collaboration (ZCS) 8.8.15 et 9.0. Un attaquant peut téléverser des fichiers arbitraires via amavis par le biais d'une faille cpio (extraction vers /opt/zimbra/jetty/webapps/zimbra/public) pouvant conduire à un accès incorrect à tout autre compte utilisateur. Zimbra recommande pax plutôt que cpio. De plus, pax figure parmi les prérequis de Zimbra sur Ubuntu ; toutefois, pax ne fait plus partie d'une installation Red Hat par défaut après RHEL 6 (ou CentOS 6). Une fois pax installé, amavis le préfère automatiquement à cpio.
- CVE-2022-3236Critique9.8
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
- CVE-2022-39197Moyenne6.1
An XSS (Cross Site Scripting) vulnerability was found in HelpSystems Cobalt Strike through 4.7 that allowed a remote attacker to execute HTML on the Cobalt Strike teamserver. To exploit the vulnerability, one must first inspect a Cobalt Strike payload, and then modify the username field in the payload (or create a new payload with the extracted information and then modify that username field to be malformed).
- CVE-2022-32917Élevée7.8
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
- CVE-2022-40139Élevée7.2
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
- CVE-2022-35914Critique9.8
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
- CVE-2022-37969Élevée7.8
Windows Common Log File System Driver Elevation of Privilege Vulnerability
- CVE-2022-27593Critique10.0
An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS 4.3.6: Photo Station 5.7.18 and later QTS 4.3.3: Photo Station 5.4.15 and later QTS 4.2.6: Photo Station 5.2.14 and later
- CVE-2022-37055Critique9.8
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer Overflow via cgibin, hnap_main,
- CVE-2022-36537Élevée7.5
ZK Framework v9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 allows attackers to access sensitive information via a crafted POST request sent to the component AuUploader.
This product uses the NVD API but is not endorsed or certified by the NVD.