Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2023-21839
Known exploited
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVSS Score
7.5
EPSS Score
0.998
Published
2023-01-18
CVE-2023-22952
Known exploited
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
CVSS Score
8.8
EPSS Score
0.803
Published
2023-01-11
CVE-2023-21674
Known exploited
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
CVSS Score
8.8
EPSS Score
0.418
Published
2023-01-10
CVE-2022-44877
Known exploited
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
CVSS Score
9.8
EPSS Score
1.0
Published
2023-01-05
CVE-2022-42475
Known exploited
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests.
CVSS Score
9.8
EPSS Score
0.995
Published
2023-01-02
CVE-2022-26485
Known exploited
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
CVSS Score
8.8
EPSS Score
0.138
Published
2022-12-22
CVE-2022-26486
Known exploited
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
CVSS Score
9.6
EPSS Score
0.023
Published
2022-12-22
CVE-2022-42856
Known exploited
A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1..
CVSS Score
8.8
EPSS Score
0.085
Published
2022-12-15
CVE-2022-44698
Known exploited
Windows SmartScreen Security Feature Bypass Vulnerability
CVSS Score
5.4
EPSS Score
0.761
Published
2022-12-13
CVE-2022-27518
Known exploited
Unauthenticated remote arbitrary code execution
CVSS Score
9.8
EPSS Score
0.069
Published
2022-12-13


Contact Us

Shodan ® - All rights reserved