Vulnerabilities (CVE)
1,704 pages, showing 1,001–1,100, ordered by identifier.
- CVE-2022-26925 — Microsoft Windows LSA Spoofing Vulnerability Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the...
- CVE-2022-27518 — Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain...
- CVE-2022-27593 — QNAP Photo Station Externally Controlled Reference Vulnerability Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a...
- CVE-2022-27924 — Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance...
- CVE-2022-27925 — Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated...
- CVE-2022-27926 — Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL...
- CVE-2022-2856 — Google Chromium Intents Insufficient Input Validation Vulnerability Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote...
- CVE-2022-28810 — Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when...
- CVE-2022-29303 — SolarView Compact Command Injection Vulnerability SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send...
- CVE-2022-29464 — WSO2 Multiple Products Unrestrictive Upload of File Vulnerability Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
- CVE-2022-29499 — Mitel MiVoice Connect Data Validation Vulnerability The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
- CVE-2022-30190 — Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application...
- CVE-2022-30333 — RARLAB UnRAR Directory Traversal Vulnerability RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files...
- CVE-2022-3038 — Google Chromium Network Service Use-After-Free Vulnerability Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially...
- CVE-2022-30525 — Zyxel Multiple Firewalls OS Command Injection Vulnerability A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to...
- CVE-2022-3075 — Google Chromium Mojo Insufficient Data Validation Vulnerability Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has...
- CVE-2022-31199 — Netwrix Auditor Insecure Object Deserialization Vulnerability Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability...
- CVE-2022-3236 — Sophos Firewall Code Injection Vulnerability A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
- CVE-2022-32893 — Apple iOS and macOS Out-of-Bounds Write Vulnerability Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when...
- CVE-2022-32894 — Apple iOS and macOS Out-of-Bounds Write Vulnerability Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code...
- CVE-2022-32917 — Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an...
- CVE-2022-33891 — Apache Spark Command Injection Vulnerability Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists...
- CVE-2022-34713 — Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a...
- CVE-2022-35405 — Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that...
- CVE-2022-35914 — Teclib GLPI Remote Code Execution Vulnerability Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
- CVE-2022-36537 — ZK Framework AuUploader Unspecified Vulnerability ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the...
- CVE-2022-36804 — Atlassian Bitbucket Server and Data Center Command Injection Vulnerability Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where...
- CVE-2022-37042 — Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet....
- CVE-2022-37055 — D-Link Routers Buffer Overflow Vulnerability D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and...
- CVE-2022-3723 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2022-37969 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for...
- CVE-2022-38028 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a...
- CVE-2022-38181 — Arm Mali GPU Kernel Driver Use-After-Free Vulnerability Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root...
- CVE-2022-39197 — Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker...
- CVE-2022-40139 — Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that...
- CVE-2022-40684 — Fortinet Multiple Products Authentication Bypass Vulnerability Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow...
- CVE-2022-40765 — Mitel MiVoice Connect Command Injection Vulnerability The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to...
- CVE-2022-40799 — D-Link DNR-322L Download of Code Without Integrity Check Vulnerability D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated...
- CVE-2022-41033 — Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2022-41040 — Microsoft Exchange Server Server-Side Request Forgery Vulnerability Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is...
- CVE-2022-41049 — Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited...
- CVE-2022-41073 — Microsoft Windows Print Spooler Privilege Escalation Vulnerability Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level...
- CVE-2022-41080 — Microsoft Exchange Server Privilege Escalation Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This...
- CVE-2022-41082 — Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution....
- CVE-2022-41091 — Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited...
- CVE-2022-41125 — Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability...
- CVE-2022-41128 — Microsoft Windows Scripting Languages Remote Code Execution Vulnerability Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote...
- CVE-2022-41223 — Mitel MiVoice Connect Code Injection Vulnerability The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to...
- CVE-2022-41328 — Fortinet FortiOS Path Traversal Vulnerability Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and...
- CVE-2022-4135 — Google Chromium GPU Heap Buffer Overflow Vulnerability Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised...
- CVE-2022-41352 — Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain...
- CVE-2022-42475 — Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an...
- CVE-2022-4262 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2022-42827 — Apple iOS and iPadOS Out-of-Bounds Write Vulnerability Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform...
- CVE-2022-42856 — Apple iOS Type Confusion Vulnerability Apple iOS contains a type confusion vulnerability when processing maliciously crafted web content leading to code execution.
- CVE-2022-42948 — Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability Fortra Cobalt Strike User Interface contains an unspecified vulnerability rooted in Java Swing that may allow remote...
- CVE-2022-43769 — Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to...
- CVE-2022-43939 — Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions...
- CVE-2022-44698 — Microsoft Defender SmartScreen Security Feature Bypass Vulnerability Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to...
- CVE-2022-44877 — CWP Control Web Panel OS Command Injection Vulnerability CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command injection vulnerability that allows remote...
- CVE-2022-46169 — Cacti Command Injection Vulnerability Cacti contains a command injection vulnerability that allows an unauthenticated user to execute code.
- CVE-2022-47966 — Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability Multiple Zoho ManageEngine products contain an unauthenticated remote code execution vulnerability due to the usage...
- CVE-2022-47986 — IBM Aspera Faspex Code Execution Vulnerability IBM Aspera Faspex could allow a remote attacker to execute code on the system, caused by a YAML deserialization flaw.
- CVE-2022-48503 — Apple Multiple Products Unspecified Vulnerability Apple macOS, iOS, tvOS, Safari, and watchOS contain an unspecified vulnerability in JavaScriptCore that when...
- CVE-2022-48618 — Apple Multiple Products Memory Corruption Vulnerability Apple iOS, iPadOS, macOS, tvOS, and watchOS contain a time-of-check/time-of-use (TOCTOU) memory corruption...
- CVE-2023-0266 — Linux Kernel Use-After-Free Vulnerability Linux kernel contains a use-after-free vulnerability that allows for privilege escalation to gain ring0 access from...
- CVE-2023-0386 — Linux Kernel Improper Ownership Management Vulnerability Linux Kernel contains an improper ownership management vulnerability, where unauthorized access to the execution of...
- CVE-2023-0669 — Fortra GoAnywhere MFT Remote Code Execution Vulnerability Fortra (formerly, HelpSystems) GoAnywhere MFT contains a pre-authentication remote code execution vulnerability in...
- CVE-2023-1389 — TP-Link Archer AX-21 Command Injection Vulnerability TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.
- CVE-2023-1671 — Sophos Web Appliance Command Injection Vulnerability Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote...
- CVE-2023-20109 — Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN)...
- CVE-2023-20118 — Cisco Small Business RV Series Routers Command Injection Vulnerability Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based...
- CVE-2023-20198 — Cisco IOS XE Web UI Privilege Escalation Vulnerability Cisco IOS XE Web UI contains a privilege escalation vulnerability in the web user interface that could allow a...
- CVE-2023-20269 — Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that...
- CVE-2023-20273 — Cisco IOS XE Web UI Command Injection Vulnerability Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198,...
- CVE-2023-2033 — Google Chromium V8 Type Confusion Vulnerability Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially...
- CVE-2023-20867 — VMware Tools Authentication Bypass Vulnerability VMware Tools contains an authentication bypass vulnerability in the vgauth module. A fully compromised ESXi host can...
- CVE-2023-20887 — Vmware Aria Operations for Networks Command Injection Vulnerability VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability...
- CVE-2023-20963 — Android Framework Privilege Escalation Vulnerability Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app...
- CVE-2023-21237 — Android Pixel Information Disclosure Vulnerability Android Pixel contains a vulnerability in the Framework component, where the UI may be misleading or insufficient,...
- CVE-2023-2136 — Google Chrome Skia Integer Overflow Vulnerability Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised...
- CVE-2023-21492 — Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability Samsung mobile devices running Android 11, 12, and 13 contain an insertion of sensitive information into log file...
- CVE-2023-21529 — Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to...
- CVE-2023-21608 — Adobe Acrobat and Reader Use-After-Free Vulnerability Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of...
- CVE-2023-21674 — Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for...
- CVE-2023-21715 — Microsoft Office Publisher Security Feature Bypass Vulnerability Microsoft Office Publisher contains a security feature bypass vulnerability that allows for a local, authenticated...
- CVE-2023-21823 — Microsoft Windows Graphic Component Privilege Escalation Vulnerability Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2023-21839 — Oracle WebLogic Server Unspecified Vulnerability Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network...
- CVE-2023-22515 — Atlassian Confluence Data Center and Server Broken Access Control Vulnerability Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker...
- CVE-2023-22518 — Atlassian Confluence Data Center and Server Improper Authorization Vulnerability Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in...
- CVE-2023-22527 — Atlassian Confluence Data Center and Server Template Injection Vulnerability Atlassian Confluence Data Center and Server contain an unauthenticated OGNL template injection vulnerability that...
- CVE-2023-22952 — Multiple SugarCRM Products Remote Code Execution Vulnerability Multiple SugarCRM products contain a remote code execution vulnerability in the EmailTemplates. Using a specially...
- CVE-2023-23376 — Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for...
- CVE-2023-23397 — Microsoft Office Outlook Privilege Escalation Vulnerability Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against...
- CVE-2023-23529 — Apple Multiple Products WebKit Type Confusion Vulnerability Apple iOS, MacOS, Safari and iPadOS WebKit contain a type confusion vulnerability that leads to code execution when...
- CVE-2023-23752 — Joomla! Improper Access Control Vulnerability Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
- CVE-2023-24489 — Citrix Content Collaboration ShareFile Improper Access Control Vulnerability Citrix Content Collaboration contains an improper access control vulnerability that could allow an unauthenticated...
- CVE-2023-24880 — Microsoft Windows SmartScreen Security Feature Bypass Vulnerability Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade...
- CVE-2023-24955 — Microsoft SharePoint Server Code Injection Vulnerability Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site...
- CVE-2023-25280 — D-Link DIR-820 Router OS Command Injection Vulnerability D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.