Vulnerabilities
Vulnerable Software
Security Vulnerabilities - Known exploited
CVE-2022-22963
Known exploited
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
CVSS Score
9.8
EPSS Score
0.999
Published
2022-04-01
CVE-2022-22965
Known exploited
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
CVSS Score
9.8
EPSS Score
0.997
Published
2022-04-01
CVE-2022-26871
Known exploited
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
CVSS Score
9.8
EPSS Score
0.196
Published
2022-03-29
CVE-2022-22948
Known exploited
The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information.
CVSS Score
6.5
EPSS Score
0.138
Published
2022-03-29
CVE-2022-26258
Known exploited
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
CVSS Score
9.8
EPSS Score
0.798
Published
2022-03-28
CVE-2022-1040
Known exploited
An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.
CVSS Score
9.8
EPSS Score
0.998
Published
2022-03-25
CVE-2022-22620
Known exploited
A use after free issue was addressed with improved memory management. This issue is fixed in macOS Monterey 12.2.1, iOS 15.3.1 and iPadOS 15.3.1, Safari 15.3 (v. 16612.4.9.1.8 and 15612.4.9.1.8). Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
CVSS Score
8.8
EPSS Score
0.163
Published
2022-03-18
CVE-2022-22587
Known exploited
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 15.3 and iPadOS 15.3, macOS Big Sur 11.6.3, macOS Monterey 12.2. A malicious application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..
CVSS Score
9.8
EPSS Score
0.116
Published
2022-03-18
CVE-2022-26500
Known exploited
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
CVSS Score
8.8
EPSS Score
0.059
Published
2022-03-17
CVE-2022-26501
Known exploited
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
CVSS Score
9.8
EPSS Score
0.043
Published
2022-03-17


Contact Us

Shodan ® - All rights reserved