Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,772 matching · page 1297/1436Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-4326(opens NVD record) | Medium | 5.5 | Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in the removal protection functionality. | Dec 16, 2022 |
| CVE-2022-4130(opens NVD record) | Medium | 4.5 | A blind site-to-site request forgery vulnerability was found in Satellite server. It is possible to trigger an external interaction to an attacker's server by modifying the Referer header in an HTTP request of specific resources in the server. | Dec 16, 2022 |
| CVE-2022-44502(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 16, 2022 |
| CVE-2022-44500(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 16, 2022 |
| CVE-2022-44499(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 16, 2022 |
| CVE-2022-44498(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.5.1 (and earlier), and 27.0 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Dec 16, 2022 |
| CVE-2022-42343(opens NVD record) | Medium | 6.5 | Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitrary requests via injection of arbitrary URLs. Exploitation of this issue does not require user interaction. | Dec 16, 2022 |
| CVE-2022-38106(opens NVD record) | Medium | 5.4 | This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. | Dec 16, 2022 |
| CVE-2022-31708(opens NVD record) | Medium | 4.9 | vRealize Operations (vROps) contains a broken access control vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.4. | Dec 16, 2022 |
| CVE-2022-31707(opens NVD record) | High | 7.2 | vRealize Operations (vROps) contains a privilege escalation vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | Dec 16, 2022 |
| CVE-2022-25628(opens NVD record) | High | 8.8 | An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 | Dec 16, 2022 |
| CVE-2022-25627(opens NVD record) | Medium | 6.7 | An authenticated administrator who has physical access to the environment can carry out Remote Command Execution on Management Console in Symantec Identity Manager 14.4 | Dec 16, 2022 |
| CVE-2022-25626(opens NVD record) | Medium | 5.3 | An unauthenticated user can access Identity Manager’s management console specific page URLs. However, the system doesn’t allow the user to carry out server side tasks without a valid web session. | Dec 16, 2022 |
| CVE-2021-35252(opens NVD record) | High | 7.5 | Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext. | Dec 16, 2022 |
| CVE-2022-4521(opens NVD record) | Low | 3.5 | A vulnerability classified as problematic has been found in WSO2 carbon-registry up to 4.8.6. This affects an unknown part of the component Request Parameter Handler. The manipulation of the argument parentPath/path/username/path/profile_menu leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 4.8.7 is able to address this issue. The name of the patch is 9f967abfde9317bee2cda469dbc09b57d539f2cc. It is recommended to upgrade the affected component. The identifier VDB-215901 was assigned to this vulnerability. | Dec 15, 2022 |
| CVE-2022-4520(opens NVD record) | Low | 3.5 | A vulnerability was found in WSO2 carbon-registry up to 4.8.11. It has been rated as problematic. Affected by this issue is some unknown functionality of the file components/registry/org.wso2.carbon.registry.search.ui/src/main/resources/web/search/advancedSearchForm-ajaxprocessor.jsp of the component Advanced Search. The manipulation of the argument mediaType/rightOp/leftOp/rightPropertyValue/leftPropertyValue leads to cross site scripting. The attack may be launched remotely. Upgrading to version 4.8.12 is able to address this issue. The name of the patch is 0c827cc1b14b82d8eb86117ab2e43c34bb91ddb4. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215900. | Dec 15, 2022 |
| CVE-2022-46768(opens NVD record) | Medium | 5.9 | Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files. | Dec 15, 2022 |
| CVE-2020-4497(opens NVD record) | Medium | 6.8 | IBM Spectrum Protect Plus 10.1.0 through 10.1.12 discloses sensitive information due to unencrypted data being used in the communication flow between Spectrum Protect Plus vSnap and its agents. An attacker could obtain information using main in the middle techniques. IBM X-Force ID: 182106. | Dec 14, 2022 |
| CVE-2022-4283(opens NVD record) | High | 7.8 | A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. | Dec 14, 2022 |
| CVE-2022-46344(opens NVD record) | High | 8.8 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclosure. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. | Dec 14, 2022 |
| CVE-2022-46343(opens NVD record) | High | 8.8 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. | Dec 14, 2022 |
| CVE-2022-46342(opens NVD record) | High | 8.8 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se | Dec 14, 2022 |
| CVE-2022-46341(opens NVD record) | High | 8.8 | A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. | Dec 14, 2022 |
| CVE-2022-46340(opens NVD record) | High | 8.8 | A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. This issue does not affect systems where client and server use the same byte order. | Dec 14, 2022 |
| CVE-2022-2601(opens NVD record) | High | 8.6 | A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this vulnerability to circumvent the secure boot mechanism. | Dec 14, 2022 |
| CVE-2022-31705(opens NVD record) | High | 8.2 | VMware ESXi, Workstation, and Fusion contain a heap out-of-bounds write vulnerability in the USB 2.0 controller (EHCI). A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. On ESXi, the exploitation is contained within the VMX sandbox whereas, on Workstation and Fusion, this may lead to code execution on the machine where Workstation or Fusion is installed. | Dec 14, 2022 |
| CVE-2022-31703(opens NVD record) | High | 7.5 | The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | Dec 14, 2022 |
| CVE-2022-31702(opens NVD record) | Critical | 9.8 | vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. | Dec 14, 2022 |
| CVE-2022-31701(opens NVD record) | Medium | 5.3 | VMware Workspace ONE Access and Identity Manager contain a broken authentication vulnerability. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 5.3. | Dec 14, 2022 |
| CVE-2022-31700(opens NVD record) | High | 7.2 | VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | Dec 14, 2022 |
| CVE-2022-31358(opens NVD record) | Critical | 9.0 | A reflected cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment prior to v7.2-3 allows remote attackers to execute arbitrary web scripts or HTML via non-existent endpoints under path /api2/html/. | Dec 14, 2022 |
| CVE-2022-4439(opens NVD record) | High | 8.8 | Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: High) | Dec 14, 2022 |
| CVE-2022-47213(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-47212(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-47211(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44713(opens NVD record) | High | 7.5 | Microsoft Outlook for Mac Spoofing Vulnerability | Dec 13, 2022 |
| CVE-2022-44710(opens NVD record) | High | 7.8 | DirectX Graphics Kernel Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44708(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44707(opens NVD record) | Medium | 6.5 | Windows Kernel Denial of Service Vulnerability | Dec 13, 2022 |
| CVE-2022-44704(opens NVD record) | High | 7.8 | Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44702(opens NVD record) | High | 7.8 | Windows Terminal Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44699(opens NVD record) | Medium | 5.5 | Azure Network Watcher Agent Security Feature Bypass Vulnerability | Dec 13, 2022 |
| CVE-2022-44698(opens NVD record) | Medium | 5.4 | Windows SmartScreen Security Feature Bypass Vulnerability | Dec 13, 2022 |
| CVE-2022-44697(opens NVD record) | High | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44696(opens NVD record) | High | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44695(opens NVD record) | High | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44694(opens NVD record) | High | 7.8 | Microsoft Office Visio Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44693(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44692(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44691(opens NVD record) | High | 7.8 | Microsoft Office OneNote Remote Code Execution Vulnerability | Dec 13, 2022 |