Base de données CVE
Archive des vulnérabilités connues (CVE) avec score CVSS, gravité, produits et éditeurs concernés. Filtrez par année et par sévérité.
- CVE-2022-0609Élevée8.8
Use after free in Animation in Google Chrome prior to 98.0.4758.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-22965Critique9.8
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
- CVE-2022-22963Critique9.8
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
- CVE-2022-26871Critique9.8
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
- CVE-2022-22948Moyenne6.5
Le vCenter Server contient une vulnérabilité de divulgation d'informations due à des autorisations de fichiers inappropriées. Un acteur malveillant disposant d'un accès non administratif au vCenter Server peut exploiter ce problème pour accéder à des informations sensibles.
- CVE-2022-26258Critique9.8
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
- CVE-2022-0995Élevée7.8
Une faille d'écriture mémoire hors limites (OOB) a été trouvée dans le sous-système de notification d'événements watch_queue du noyau Linux. Cette faille peut écraser des parties de l'état du noyau, permettant potentiellement à un utilisateur local d'obtenir un accès privilégié ou de provoquer un déni de service sur le système.
- CVE-2022-1040Critique9.8
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
- CVE-2022-22620Élevée8.8
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
- CVE-2022-22587Critique9.8
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
- CVE-2022-26501Critique9.8
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
- CVE-2022-26500Élevée8.8
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
- CVE-2021-39793Élevée7.8
In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A
- CVE-2022-26143Critique9.8
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
- CVE-2022-0847Élevée7.8
Une faille a été trouvée dans la manière dont le membre "flags" de la nouvelle structure pipe buffer manquait d'initialisation appropriée dans les fonctions copy_page_to_iter_pipe et push_pipe du noyau Linux et pouvait donc contenir des valeurs obsolètes. Un utilisateur local non privilégié pouvait utiliser cette faille pour écrire dans des pages du page cache adossées à des fichiers en lecture seule et ainsi élever ses privilèges sur le système.
- CVE-2022-26318Critique9.8
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
- CVE-2022-22947Critique10.0
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted request that could allow arbitrary remote execution on the remote host.
- CVE-2022-0492Élevée7.8
Une vulnérabilité a été trouvée dans la fonction cgroup_release_agent_write du noyau Linux dans kernel/cgroup/cgroup-v1.c. Cette faille, dans certaines circonstances, permet l'utilisation de la fonctionnalité release_agent de cgroups v1 pour élever les privilèges et contourner de manière inattendue l'isolation des namespaces.
- CVE-2022-22706Élevée7.8
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
- CVE-2022-24346Élevée7.8
Dans JetBrains IntelliJ IDEA avant 2021.3.1, l'exécution de code local via des caractères RLO (Right-to-Left Override) était possible.
This product uses the NVD API but is not endorsed or certified by the NVD.