Exploited vulnerabilities

CVEs published in the last 120 days, plus everything on CISA’s known-exploited list. Scores, exploit likelihood and exploitation status in one place.

47,416 CVEs · 1,734 known exploited · CVE data updated 1 hour ago · EPSS 3 hours ago

1,734 results · page 36 of 87 EPSS = probability of exploitation in the next 30 days (FIRST)
Matching CVEs
Score CVE Affected EPSS Published
9.6 critical CVE-2022-26486 KEV Mozilla Firefox An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0. 2.4% 22 Dec 2022
8.8 high CVE-2022-26485 KEV Mozilla Firefox Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0. 14% 22 Dec 2022
8.8 high CVE-2022-42856 KEV Apple tvOS A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.1.2. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.1.. 8.5% 15 Dec 2022
5.4 medium CVE-2022-44698 KEV Microsoft Windows 10 Version 1809 Windows SmartScreen Security Feature Bypass Vulnerability 76% 13 Dec 2022
9.8 critical CVE-2022-27518 KEV Citrix Gateway, Citrix ADC Unauthenticated remote arbitrary code execution 6.7% 13 Dec 2022
9.8 critical CVE-2022-46169 KEV cacti Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbitrary code on a server running Cacti, if a specific data source was selected for any monitored device. The vulnerability resides in the `remote_agent.php` file. This file can be accessed without authentication. This function retrieves the IP address of the client via `get_client_addr` and resolves this IP address to the corresponding hostname via `gethostbyaddr`. After this, it is verified that an entry within the `poller` table exists, where the hostname corresponds to the resolved hostname. If such an entry was found, the function returns `true` and the client is authorized. This authorization can be bypassed due to the implementation of the `get_client_addr` function. The function is defined in the file `lib/functions.php` and checks serval `$_SERVER` variables to determine the IP address of the client. The variables beginning with `HTTP_` can be arbitrarily set by an attacker. Since there is a default entry in the `poller` table with the hostname of the server running Cacti, an attacker can bypass the authentication e.g. by providing the header `Forwarded-For: <TARGETIP>`. This way the function `get_client_addr` returns the IP address of the server running Cacti. The following call to `gethostbyaddr` will resolve this IP address to the hostname of the server, which will pass the `poller` hostname check because of the default entry. After the authorization of the `remote_agent.php` file is bypassed, an attacker can trigger different actions. One of these actions is called `polldata`. The called function `poll_for_data` retrieves a few request parameters and loads the corresponding `poller_item` entries from the database. If the `action` of a `poller_item` equals `POLLER_ACTION_SCRIPT_PHP`, the function `proc_open` is used to execute a PHP script. The attacker-controlled parameter `$poller_id` is retrieved via the function `get_nfilter_request_var`, which allows arbitrary strings. This variable is later inserted into the string passed to `proc_open`, which leads to a command injection vulnerability. By e.g. providing the `poller_id=;id` the `id` command is executed. In order to reach the vulnerable call, the attacker must provide a `host_id` and `local_data_id`, where the `action` of the corresponding `poller_item` is set to `POLLER_ACTION_SCRIPT_PHP`. Both of these ids (`host_id` and `local_data_id`) can easily be bruteforced. The only requirement is that a `poller_item` with an `POLLER_ACTION_SCRIPT_PHP` action exists. This is very likely on a productive instance because this action is added by some predefined templates like `Device - Uptime` or `Device - Polling Time`. This command injection vulnerability allows an unauthenticated user to execute arbitrary commands if a `poller_item` with the `action` type `POLLER_ACTION_SCRIPT_PHP` (`2`) is configured. The authorization bypass should be prevented by not allowing an attacker to make `get_client_addr` (file `lib/functions.php`) return an arbitrary IP address. This could be done by not honoring the `HTTP_...` `$_SERVER` variables. If these should be kept for compatibility reasons it should at least be prevented to fake the IP address of the server running Cacti. This vulnerability has been addressed in both the 1.2.x and 1.3.x release branches with `1.2.23` being the first release containing the patch. >99% 5 Dec 2022
8.8 high CVE-2022-4262 KEV Google Chrome Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 24% 2 Dec 2022
8.8 high CVE-2022-40799 KEV dlink dnr-322l firmware Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. 34% 29 Nov 2022
9.6 critical CVE-2022-4135 KEV Google Chrome Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) 32% 25 Nov 2022
6.8 medium CVE-2022-41223 KEV mitel mivoice connect The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type. 11% 22 Nov 2022
6.8 medium CVE-2022-40765 KEV mitel mivoice connect A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters. 11% 22 Nov 2022
7.8 high CVE-2022-23748 KEV Audinate Dante Application Library for Windows mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files. 9.1% 17 Nov 2022
8.8 high CVE-2022-41128 KEV Microsoft Windows 10 Version 1507 Windows Scripting Languages Remote Code Execution Vulnerability 25% 9 Nov 2022
7.8 high CVE-2022-41125 KEV Microsoft Windows 10 Version 1507 Windows CNG Key Isolation Service Elevation of Privilege Vulnerability 3.0% 9 Nov 2022
5.4 medium CVE-2022-41091 KEV Microsoft Windows 10 Version 1507 Windows Mark of the Web Security Feature Bypass Vulnerability 1.8% 9 Nov 2022
8.8 high CVE-2022-41080 KEV Microsoft Exchange Server 2013 Cumulative Update 23 Microsoft Exchange Server Elevation of Privilege Vulnerability 77% 9 Nov 2022
7.8 high CVE-2022-41073 KEV Microsoft Windows 10 Version 1507 Windows Print Spooler Elevation of Privilege Vulnerability 2.3% 9 Nov 2022
5.4 medium CVE-2022-41049 KEV Microsoft Windows 10 Version 1507 Windows Mark of the Web Security Feature Bypass Vulnerability 2.5% 9 Nov 2022
9.8 critical CVE-2022-31199 KEV netwrix auditor Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors. 36% 8 Nov 2022
8.8 high CVE-2022-3723 KEV Google Chrome Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 7.9% 1 Nov 2022