Vulnerabilities (CVE)
1,704 pages, showing 901–1,000, ordered by identifier.
- CVE-2021-4034 — Red Hat Polkit Out-of-Bounds Read and Write Vulnerability The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege...
- CVE-2021-40407 — Reolink RLC-410W IP Camera OS Command Injection Vulnerability Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network...
- CVE-2021-40438 — Apache HTTP Server-Side Request Forgery (SSRF) A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote...
- CVE-2021-40444 — Microsoft MSHTML Remote Code Execution Vulnerability Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
- CVE-2021-40449 — Microsoft Windows Win32k Privilege Escalation Vulnerability Unspecified vulnerability allows for an authenticated user to escalate privileges.
- CVE-2021-40450 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-40539 — Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability Zoho ManageEngine ADSelfService Plus contains an authentication bypass vulnerability affecting the REST API URLs...
- CVE-2021-40655 — D-Link DIR-605 Router Information Disclosure Vulnerability D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username...
- CVE-2021-40870 — Aviatrix Controller Unrestricted Upload of File Unrestricted upload of a file with a dangerous type is possible, which allows an unauthenticated user to execute...
- CVE-2021-4102 — Google Chromium V8 Use-After-Free Vulnerability Google Chromium V8 Engine contains a use-after-free vulnerability that allows a remote attacker to potentially...
- CVE-2021-41277 — Metabase GeoJSON API Local File Inclusion Vulnerability Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
- CVE-2021-41357 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-41379 — Microsoft Windows Installer Privilege Escalation Vulnerability Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-41773 — Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution...
- CVE-2021-42013 — Apache HTTP Server Path Traversal Vulnerability Apache HTTP Server contains a path traversal vulnerability that allows an attacker to perform remote code execution...
- CVE-2021-42237 — Sitecore XP Remote Command Execution Vulnerability Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.
- CVE-2021-42258 — BQE BillQuick Web Suite SQL Injection Vulnerability BQE BillQuick Web Suite contains an SQL injection vulnerability when accessing the username parameter that may allow...
- CVE-2021-42278 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-42287 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-42292 — Microsoft Excel Security Feature Bypass A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.
- CVE-2021-42321 — Microsoft Exchange Server Remote Code Execution Vulnerability An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and...
- CVE-2021-43226 — Microsoft Windows Privilege Escalation Vulnerability Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a...
- CVE-2021-43798 — Grafana Path Traversal Vulnerability Grafana contains a path traversal vulnerability that could allow access to local files.
- CVE-2021-43890 — Microsoft Windows AppX Installer Spoofing Vulnerability Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality,...
- CVE-2021-44026 — Roundcube Webmail SQL Injection Vulnerability Roundcube Webmail is vulnerable to SQL injection via search or search_params.
- CVE-2021-44077 — Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability Zoho ManageEngine ServiceDesk Plus before 11306, ServiceDesk Plus MSP before 10530, and SupportCenter Plus before...
- CVE-2021-44168 — Fortinet FortiOS Arbitrary File Download Fortinet FortiOS "execute restore src-vis" downloads code without integrity checking, allowing an attacker to...
- CVE-2021-44207 — Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve...
- CVE-2021-44228 — Apache Log4j2 Remote Code Execution Vulnerability Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related...
- CVE-2021-44515 — Zoho Desktop Central Authentication Bypass Vulnerability Zoho Desktop Central contains an authentication bypass vulnerability that could allow an attacker to execute...
- CVE-2021-44529 — Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an...
- CVE-2021-45046 — Apache Log4j2 Deserialization of Untrusted Data Vulnerability Apache Log4j2 contains a deserialization of untrusted data vulnerability due to the incomplete fix of...
- CVE-2021-45382 — D-Link Multiple Routers Remote Code Execution Vulnerability A remote code execution vulnerability exists in all series H/W revisions routers via the DDNS function in ncc2 binary file.
- CVE-2022-0028 — Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct...
- CVE-2022-0185 — Linux Kernel Heap-Based Buffer Overflow Vulnerability Linux kernel contains a heap-based buffer overflow vulnerability in the legacyparseparam function in the Filesystem...
- CVE-2022-0492 — Linux Kernel Improper Authentication Vulnerability Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the...
- CVE-2022-0543 — Debian-specific Redis Server Lua Sandbox Escape Vulnerability Redis is prone to a (Debian-specific) Lua sandbox escape, which could result in remote code execution.
- CVE-2022-0609 — Google Chromium Animation Use-After-Free Vulnerability Google Chromium Animation contains a use-after-free vulnerability that allows a remote attacker to potentially...
- CVE-2022-0847 — Linux Kernel Privilege Escalation Vulnerability Linux kernel contains an improper initialization vulnerability where an unprivileged local user could escalate their...
- CVE-2022-0995 — Linux Kernel Out-of-Bounds Write Vulnerability Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged...
- CVE-2022-1040 — Sophos Firewall Authentication Bypass Vulnerability An authentication bypass vulnerability in User Portal and Webadmin of Sophos Firewall allows for remote code execution.
- CVE-2022-1096 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2022-1364 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2022-1388 — F5 BIG-IP Missing Authentication Vulnerability F5 BIG-IP contains a missing authentication in critical function vulnerability which can allow for remote code...
- CVE-2022-20699 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do...
- CVE-2022-20700 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do...
- CVE-2022-20701 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do...
- CVE-2022-20703 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do...
- CVE-2022-20708 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do...
- CVE-2022-20775 — Cisco SD-WAN Path Traversal Vulnerability Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain...
- CVE-2022-20821 — Cisco IOS XR Open Port Vulnerability Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the...
- CVE-2022-21445 — Oracle ADF Faces Deserialization of Untrusted Data Vulnerability Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data...
- CVE-2022-21587 — Oracle E-Business Suite Unspecified Vulnerability Oracle E-Business Suite contains an unspecified vulnerability that allows an unauthenticated attacker with network...
- CVE-2022-21882 — Microsoft Win32k Privilege Escalation Vulnerability Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2022-21919 — Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2022-21971 — Microsoft Windows Runtime Remote Code Execution Vulnerability Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
- CVE-2022-21999 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
- CVE-2022-22047 — Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
- CVE-2022-22071 — Qualcomm Multiple Chipsets Use-After-Free Vulnerability Multiple Qualcomm chipsets contain a use-after-free vulnerability when process shell memory is freed using IOCTL...
- CVE-2022-22265 — Samsung Mobile Devices Use-After-Free Vulnerability Samsung devices with selected Exynos chipsets contain a use-after-free vulnerability that allows malicious memory...
- CVE-2022-22536 — SAP Multiple Products HTTP Request Smuggling Vulnerability SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and...
- CVE-2022-22587 — Apple Memory Corruption Vulnerability Apple IOMobileFrameBuffer contains a memory corruption vulnerability which can allow a malicious application to...
- CVE-2022-22620 — Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability Apple iOS, iPadOS, and macOS WebKit contain a use-after-free vulnerability that leads to code execution when...
- CVE-2022-22674 — Apple macOS Out-of-Bounds Read Vulnerability macOS Monterey contains an out-of-bounds read vulnerability that could allow an application to read kernel memory.
- CVE-2022-22675 — Apple macOS Out-of-Bounds Write Vulnerability macOS Monterey contains an out-of-bounds write vulnerability that could allow an application to execute arbitrary...
- CVE-2022-22706 — Arm Mali GPU Kernel Driver Unspecified Vulnerability Arm Mali GPU Kernel Driver contains an unspecified vulnerability that allows a non-privileged user to achieve write...
- CVE-2022-22718 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability which allow for privilege escalation.
- CVE-2022-2294 — WebRTC Heap Buffer Overflow Vulnerability WebRTC, an open-source project providing web browsers with real-time communication, contains a heap buffer overflow...
- CVE-2022-22947 — VMware Spring Cloud Gateway Code Injection Vulnerability Spring Cloud Gateway applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is...
- CVE-2022-22948 — VMware vCenter Server Incorrect Default File Permissions Vulnerability VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged...
- CVE-2022-22954 — VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability VMware Workspace ONE Access and Identity Manager allow for remote code execution due to server-side template injection.
- CVE-2022-22960 — VMware Multiple Products Privilege Escalation Vulnerability VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability...
- CVE-2022-22963 — VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability When using routing functionality in VMware Tanzu's Spring Cloud Function, it is possible for a user to provide a...
- CVE-2022-22965 — Spring Framework JDK 9+ Remote Code Execution Vulnerability Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
- CVE-2022-23131 — Zabbix Frontend Authentication Bypass Vulnerability Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with...
- CVE-2022-23134 — Zabbix Frontend Improper Access Control Vulnerability Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.
- CVE-2022-23176 — WatchGuard Firebox and XTM Privilege Escalation Vulnerability WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system...
- CVE-2022-23227 — NUUO NVRmini2 Devices Missing Authentication Vulnerability NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to...
- CVE-2022-23748 — Dante Discovery Process Control Vulnerability Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading...
- CVE-2022-24086 — Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for...
- CVE-2022-24112 — Apache APISIX Authentication Bypass Vulnerability Apache APISIX contains an authentication bypass vulnerability that allows for remote code execution.
- CVE-2022-24521 — Microsoft Windows CLFS Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for...
- CVE-2022-24682 — Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature...
- CVE-2022-24706 — Apache CouchDB Insecure Default Initialization of Resource Vulnerability Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to...
- CVE-2022-24816 — OSGeo GeoServer JAI-EXT Code Injection Vulnerability OSGeo GeoServer JAI-EXT contains a code injection vulnerability that, when programs use jt-jiffle and allow Jiffle...
- CVE-2022-24990 — TerraMaster OS Remote Command Execution Vulnerability TerraMaster OS contains a remote command execution vulnerability that allows an unauthenticated user to execute...
- CVE-2022-2586 — Linux Kernel Use-After-Free Vulnerability Linux Kernel contains a use-after-free vulnerability in the nft_object, allowing local attackers to escalate privileges.
- CVE-2022-26134 — Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an...
- CVE-2022-26138 — Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext....
- CVE-2022-26143 — MiCollab, MiVoice Business Express Access Control Vulnerability A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to...
- CVE-2022-26258 — D-Link DIR-820L Remote Code Execution Vulnerability D-Link DIR-820L contains an unspecified vulnerability in Device Name parameter in /lan.asp which allows for remote...
- CVE-2022-26318 — WatchGuard Firebox and XTM Appliances Arbitrary Code Execution On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.
- CVE-2022-26352 — dotCMS Unrestricted Upload of File Vulnerability dotCMS ContentResource API contains an unrestricted upload of file with a dangerous type vulnerability that allows...
- CVE-2022-26485 — Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to...
- CVE-2022-26486 — Mozilla Firefox Use-After-Free Vulnerability Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform...
- CVE-2022-26500 — Veeam Backup & Replication Remote Code Execution Vulnerability The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access...
- CVE-2022-26501 — Veeam Backup & Replication Remote Code Execution Vulnerability The Veeam Distribution Service in the Backup & Replication application allows unauthenticated users to access...
- CVE-2022-26871 — Trend Micro Apex Central Arbitrary File Upload Vulnerability An arbitrary file upload vulnerability in Trend Micro Apex Central could allow for remote code execution.
- CVE-2022-26904 — Microsoft Windows User Profile Service Privilege Escalation Vulnerability Microsoft Windows User Profile Service contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2022-26923 — Microsoft Active Directory Domain Services Privilege Escalation Vulnerability An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.