Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2022-21587
Known exploited
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks of this vulnerability can result in takeover of Oracle Web Applications Desktop Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
CVSS Score
9.8
EPSS Score
0.983
Published
2022-10-18
CVE-2022-40684
Known exploited
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an unauthenticated atttacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
CVSS Score
9.8
EPSS Score
1.0
Published
2022-10-18
CVE-2022-41033
Known exploited
Windows COM+ Event System Service Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.018
Published
2022-10-11
CVE-2022-38028
Known exploited
Windows Print Spooler Elevation of Privilege Vulnerability
CVSS Score
7.8
EPSS Score
0.149
Published
2022-10-11
CVE-2022-41040
Known exploited
Microsoft Exchange Server Elevation of Privilege Vulnerability
CVSS Score
8.8
EPSS Score
1.0
Published
2022-10-03
CVE-2022-41082
Known exploited
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS Score
8.0
EPSS Score
1.0
Published
2022-10-03
CVE-2022-20775
Known exploited
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulnerability by running a maliciously crafted command on the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sd-wan-priv-E6e8tEdF
CVSS Score
7.8
EPSS Score
0.125
Published
2022-09-30
CVE-2022-3075
Known exploited
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVSS Score
9.6
EPSS Score
0.057
Published
2022-09-26
CVE-2022-2856
Known exploited
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
CVSS Score
6.5
EPSS Score
0.045
Published
2022-09-26
CVE-2022-3038
Known exploited
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVSS Score
8.8
EPSS Score
0.247
Published
2022-09-26


Contact Us

Shodan ® - All rights reserved