Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
71,857 matching · page 1308/1438Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-38014(opens NVD record) | High | 7.0 | Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37992(opens NVD record) | High | 7.8 | Windows Group Policy Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37967(opens NVD record) | High | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-37966(opens NVD record) | High | 8.1 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | Nov 9, 2022 |
| CVE-2022-44563(opens NVD record) | Medium | 5.9 | There is a race condition vulnerability in SD upgrade mode. Successful exploitation of this vulnerability may affect data confidentiality. | Nov 9, 2022 |
| CVE-2022-44562(opens NVD record) | Critical | 9.8 | The system framework layer has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | Nov 9, 2022 |
| CVE-2022-44561(opens NVD record) | High | 7.5 | The preset launcher module has a permission verification vulnerability. Successful exploitation of this vulnerability makes unauthorized apps add arbitrary widgets and shortcuts without interaction. | Nov 9, 2022 |
| CVE-2022-44560(opens NVD record) | Medium | 5.3 | The launcher module has an Intent redirection vulnerability. Successful exploitation of this vulnerability may cause launcher module data to be modified. | Nov 9, 2022 |
| CVE-2022-44559(opens NVD record) | Critical | 9.8 | The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | Nov 9, 2022 |
| CVE-2022-44558(opens NVD record) | Critical | 9.8 | The AMS module has a vulnerability of serialization/deserialization mismatch. Successful exploitation of this vulnerability may cause privilege escalation. | Nov 9, 2022 |
| CVE-2022-44557(opens NVD record) | High | 7.5 | The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality. | Nov 9, 2022 |
| CVE-2022-44555(opens NVD record) | High | 7.5 | The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable. | Nov 9, 2022 |
| CVE-2022-44554(opens NVD record) | High | 7.5 | The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device. | Nov 9, 2022 |
| CVE-2022-44553(opens NVD record) | Medium | 5.3 | The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically. | Nov 9, 2022 |
| CVE-2022-44552(opens NVD record) | High | 7.5 | The lock screen module has defects introduced in the design process. Successful exploitation of this vulnerability may affect system availability. | Nov 9, 2022 |
| CVE-2022-44551(opens NVD record) | Critical | 9.8 | The iaware module has a vulnerability in thread security. Successful exploitation of this vulnerability will affect confidentiality, integrity, and availability. | Nov 9, 2022 |
| CVE-2022-44550(opens NVD record) | High | 7.5 | The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability. | Nov 9, 2022 |
| CVE-2022-44549(opens NVD record) | High | 7.5 | The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality. | Nov 9, 2022 |
| CVE-2022-44548(opens NVD record) | Medium | 4.3 | There is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may cause the dialog box for confirming the pairing not to be displayed during Bluetooth pairing. | Nov 9, 2022 |
| CVE-2022-44547(opens NVD record) | High | 7.5 | The Display Service module has a UAF vulnerability. Successful exploitation of this vulnerability may affect the display service availability. | Nov 9, 2022 |
| CVE-2022-44546(opens NVD record) | High | 7.5 | The kernel module has the vulnerability that the mapping is not cleared after the memory is automatically released. Successful exploitation of this vulnerability may cause a system restart. | Nov 9, 2022 |
| CVE-2022-31689(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. | Nov 9, 2022 |
| CVE-2022-31688(opens NVD record) | Medium | 6.1 | VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | Nov 9, 2022 |
| CVE-2022-31687(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | Nov 9, 2022 |
| CVE-2022-31686(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | Nov 9, 2022 |
| CVE-2022-31685(opens NVD record) | Critical | 9.8 | VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | Nov 9, 2022 |
| CVE-2022-27674(opens NVD record) | High | 7.5 | Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. | Nov 9, 2022 |
| CVE-2022-23831(opens NVD record) | High | 7.5 | Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service. | Nov 9, 2022 |
| CVE-2021-46852(opens NVD record) | High | 7.5 | The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality. | Nov 9, 2022 |
| CVE-2021-46851(opens NVD record) | Critical | 9.8 | The DRM module has a vulnerability in verifying the secure memory attributes. Successful exploitation of this vulnerability may cause abnormal video playback. | Nov 9, 2022 |
| CVE-2022-0031(opens NVD record) | Medium | 6.7 | A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges. | Nov 9, 2022 |
| CVE-2022-41978(opens NVD record) | High | 8.8 | Auth. (subscriber+) Arbitrary Options Update vulnerability in Zoho CRM Lead Magnet plugin <= 1.7.5.8 on WordPress. | Nov 9, 2022 |
| CVE-2022-43321(opens NVD record) | Medium | 6.1 | Shopwind v3.4.3 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in the component /common/library/Page.php. | Nov 9, 2022 |
| CVE-2022-45061(opens NVD record) | High | 7.5 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a malicious actor; in such a scenario, they could trigger excessive CPU consumption on the client attempting to make use of an attacker-supplied supposed hostname. For example, the attack payload could be placed in the Location header of an HTTP response with status code 302. A fix is planned in 3.11.1, 3.10.9, 3.9.16, 3.8.16, and 3.7.16. | Nov 9, 2022 |
| CVE-2022-41205(opens NVD record) | Medium | 5.5 | SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application. | Nov 8, 2022 |
| CVE-2022-3821(opens NVD record) | Medium | 5.5 | An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service. | Nov 8, 2022 |
| CVE-2022-27516(opens NVD record) | Medium | 5.3 | User login brute force protection functionality bypass | Nov 8, 2022 |
| CVE-2022-27513(opens NVD record) | High | 8.3 | Remote desktop takeover via phishing | Nov 8, 2022 |
| CVE-2022-27510(opens NVD record) | Critical | 9.8 | Unauthorized access to Gateway user capabilities | Nov 8, 2022 |
| CVE-2022-44556(opens NVD record) | High | 7.5 | Missing parameter type validation in the DRM module. Successful exploitation of this vulnerability may affect availability. | Nov 8, 2022 |
| CVE-2022-39343(opens NVD record) | Medium | 5.6 | Azure RTOS FileX is a FAT-compatible file system that’s fully integrated with Azure RTOS ThreadX. In versions before 6.2.0, the Fault Tolerant feature of Azure RTOS FileX includes integer under and overflows which may be exploited to achieve buffer overflow and modify memory contents. When a valid log file with correct ID and checksum is detected by the `_fx_fault_tolerant_enable` function an attempt to recover the previous failed write operation is taken by call of `_fx_fault_tolerant_apply_logs`. This function iterates through the log entries and performs required recovery operations. When properly crafted a log including entries of type `FX_FAULT_TOLERANT_DIR_LOG_TYPE` may be utilized to introduce unexpected behavior. This issue has been patched in version 6.2.0. A workaround to fix line 218 in fx_fault_tolerant_apply_logs.c is documented in the GHSA. | Nov 8, 2022 |
| CVE-2022-36077(opens NVD record) | High | 7.2 | The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer following the redirect, but if the redirect target is a SMB URL such as `file://some.website.com/`, then in some cases, Windows will connect to that server and attempt NTLM authentication, which can include sending hashed credentials.This issue has been patched in versions: 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7. Users are recommended to upgrade to the latest stable version of Electron. If upgrading isn't possible, this issue can be addressed without upgrading by preventing redirects to file:// URLs in the `WebContents.on('will-redirect')` event, for all WebContents as a workaround. | Nov 8, 2022 |
| CVE-2022-2188(opens NVD record) | Medium | 6.5 | Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker. | Nov 7, 2022 |
| CVE-2022-44793(opens NVD record) | Medium | 6.5 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | Nov 7, 2022 |
| CVE-2022-44792(opens NVD record) | Medium | 6.5 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | Nov 7, 2022 |
| CVE-2022-39344(opens NVD record) | Critical | 9.8 | Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass security features or execute arbitrary code. The implementation of `ux_device_class_dfu_control_request` function prevents buffer overflow during handling of DFU UPLOAD command when current state is `UX_SYSTEM_DFU_STATE_DFU_IDLE`. This issue has been patched, please upgrade to version 6.1.12. As a workaround, add the `UPLOAD_LENGTH` check in all possible states. | Nov 4, 2022 |
| CVE-2022-43945(opens NVD record) | High | 7.5 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by sending an RPC message over TCP with garbage data added at the end of the message. The RPC message with garbage data is still correctly formed according to the specification and is passed forward to handlers. Vulnerable code in NFSD is not expecting the oversized request and writes beyond the allocated buffer space. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H | Nov 4, 2022 |
| CVE-2022-31691(opens NVD record) | Critical | 9.8 | Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing support. This library allows for some special syntax in the YAML that under certain circumstances allows for potentially harmful remote code execution by the attacker. | Nov 4, 2022 |
| CVE-2022-20969(opens NVD record) | Medium | 4.8 | A vulnerability in multiple management dashboard pages of Cisco Umbrella could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the Cisco Umbrella dashboard. This vulnerability is due to unsanitized user input. An attacker could exploit this vulnerability by submitting custom JavaScript to the web application and persuading a user of the interface to click a maliciously crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or access sensitive browser-based information. | Nov 4, 2022 |
| CVE-2022-20963(opens NVD record) | Medium | 5.4 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker would need valid credentials to access the web-based management interface of an affected device. | Nov 4, 2022 |