Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,772 matching · page 1298/1436Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-44690(opens NVD record) | High | 8.8 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44689(opens NVD record) | High | 7.8 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44688(opens NVD record) | Medium | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Dec 13, 2022 |
| CVE-2022-44687(opens NVD record) | High | 7.8 | Raw Image Extension Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44683(opens NVD record) | High | 7.8 | Windows Kernel Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44682(opens NVD record) | Medium | 6.8 | Windows Hyper-V Denial of Service Vulnerability | Dec 13, 2022 |
| CVE-2022-44681(opens NVD record) | High | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44680(opens NVD record) | High | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44679(opens NVD record) | Medium | 6.5 | Windows Graphics Component Information Disclosure Vulnerability | Dec 13, 2022 |
| CVE-2022-44678(opens NVD record) | High | 7.8 | Windows Print Spooler Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44677(opens NVD record) | High | 7.8 | Windows Projected File System Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44676(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44675(opens NVD record) | High | 7.8 | Windows Bluetooth Driver Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44674(opens NVD record) | Medium | 5.5 | Windows Bluetooth Driver Information Disclosure Vulnerability | Dec 13, 2022 |
| CVE-2022-44673(opens NVD record) | High | 7.0 | Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44671(opens NVD record) | High | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44670(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44669(opens NVD record) | High | 7.0 | Windows Error Reporting Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-44668(opens NVD record) | High | 7.8 | Windows Media Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44667(opens NVD record) | High | 7.8 | Windows Media Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-44666(opens NVD record) | High | 7.8 | Windows Contacts Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-41127(opens NVD record) | High | 8.5 | Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-41121(opens NVD record) | High | 7.8 | Windows Graphics Component Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-41115(opens NVD record) | Medium | 6.6 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-41094(opens NVD record) | High | 7.8 | Windows Hyper-V Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-41089(opens NVD record) | High | 7.8 | .NET Framework Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-41077(opens NVD record) | High | 7.8 | Windows Fax Compose Form Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-41076(opens NVD record) | High | 8.5 | PowerShell Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-41074(opens NVD record) | Medium | 5.5 | Windows Graphics Component Information Disclosure Vulnerability | Dec 13, 2022 |
| CVE-2022-26806(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-26805(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-26804(opens NVD record) | High | 7.8 | Microsoft Office Graphics Remote Code Execution Vulnerability | Dec 13, 2022 |
| CVE-2022-24480(opens NVD record) | Medium | 6.3 | Outlook for Android Elevation of Privilege Vulnerability | Dec 13, 2022 |
| CVE-2022-27518(opens NVD record) | Critical | 9.8 | Unauthenticated remote arbitrary code execution | Dec 13, 2022 |
| CVE-2022-31699(opens NVD record) | Low | 3.3 | VMware ESXi contains a heap-overflow vulnerability. A malicious local actor with restricted privileges within a sandbox process may exploit this issue to achieve a partial information disclosure. | Dec 13, 2022 |
| CVE-2022-31698(opens NVD record) | Medium | 5.3 | The vCenter Server contains a denial-of-service vulnerability in the content library service. A malicious actor with network access to port 443 on vCenter Server may exploit this issue to trigger a denial-of-service condition by sending a specially crafted header. | Dec 13, 2022 |
| CVE-2022-31697(opens NVD record) | Medium | 5.5 | The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation. | Dec 13, 2022 |
| CVE-2022-31696(opens NVD record) | High | 8.8 | VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. | Dec 13, 2022 |
| CVE-2022-44303(opens NVD record) | Medium | 6.1 | Resque Scheduler version 1.27.4 is vulnerable to Cross-site scripting (XSS). A remote attacker could inject javascript code to the "{schedule_job}" or "args" parameter in /resque/delayed/jobs/{schedule_job}?args={args_id} to execute javascript at client side. | Dec 13, 2022 |
| CVE-2021-32415(opens NVD record) | High | 7.8 | EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates. | Dec 13, 2022 |
| CVE-2022-23505(opens NVD record) | Medium | 5.3 | Passport-wsfed-saml2 is a ws-federation protocol and SAML2 tokens authentication provider for Passport. In versions prior to 4.6.3, a remote attacker may be able to bypass WSFed authentication on a website using passport-wsfed-saml2. A successful attack requires that the attacker is in possession of an arbitrary IDP signed assertion. Depending on the IDP used, fully unauthenticated attacks (e.g without access to a valid user) might also be feasible if generation of a signed message can be triggered. This issue is patched in version 4.6.3. Use of SAML2 authentication instead of WSFed is a workaround. | Dec 13, 2022 |
| CVE-2022-41261(opens NVD record) | Medium | 6.0 | SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Successful exploitation can make the attacker access files and systems for which he/she is not authorized. | Dec 12, 2022 |
| CVE-2022-4312(opens NVD record) | Medium | 5.5 | A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discover the associated simple mail transfer protocol (SMTP) account credentials and the SIM card PIN code. Successful exploitation of this vulnerability could allow an unauthorized user access to the underlying email account and SIM card. | Dec 12, 2022 |
| CVE-2022-4311(opens NVD record) | Medium | 4.7 | An insertion of sensitive information into log file vulnerability exists in PcVue versions 15 through 15.2.2. This could allow a user with access to the log files to discover connection strings of data sources configured for the DbConnect, which could include credentials. Successful exploitation of this vulnerability could allow other users unauthorized access to the underlying data sources. | Dec 12, 2022 |
| CVE-2022-44654(opens NVD record) | High | 7.5 | Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied without the /SAFESEH memory protection mechanism which helps to monitor for malicious payloads. The affected component's memory protection mechanism has been updated to enhance product security. | Dec 12, 2022 |
| CVE-2022-44653(opens NVD record) | High | 7.8 | A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Dec 12, 2022 |
| CVE-2022-44652(opens NVD record) | High | 7.8 | An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Dec 12, 2022 |
| CVE-2022-44651(opens NVD record) | High | 7.0 | A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Dec 12, 2022 |
| CVE-2022-44650(opens NVD record) | High | 7.8 | A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Dec 12, 2022 |
| CVE-2022-44649(opens NVD record) | High | 7.8 | An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | Dec 12, 2022 |