Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,155 matching · page 1341/1444Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-34706(opens NVD record) | High | 7.8 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-34705(opens NVD record) | High | 7.8 | Windows Defender Credential Guard Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-34704(opens NVD record) | Medium | 4.7 | Windows Defender Credential Guard Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-34703(opens NVD record) | High | 7.8 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-34702(opens NVD record) | High | 8.1 | Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-34701(opens NVD record) | High | 7.5 | Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | Aug 9, 2022 |
| CVE-2022-34699(opens NVD record) | High | 7.8 | Windows Win32k Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-34696(opens NVD record) | High | 7.8 | Windows Hyper-V Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-34692(opens NVD record) | Medium | 5.3 | Microsoft Exchange Server Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-34691(opens NVD record) | High | 8.8 | Active Directory Domain Services Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-34690(opens NVD record) | High | 7.1 | Windows Fax Service Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-34687(opens NVD record) | High | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-34686(opens NVD record) | Medium | 5.5 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-34685(opens NVD record) | Medium | 5.5 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-33670(opens NVD record) | High | 7.8 | Windows Partition Management Driver Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-33649(opens NVD record) | Critical | 9.6 | Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | Aug 9, 2022 |
| CVE-2022-33648(opens NVD record) | High | 7.8 | Microsoft Excel Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-33646(opens NVD record) | High | 7.0 | Azure Batch Node Agent Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-33640(opens NVD record) | High | 7.8 | System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-33636(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-33631(opens NVD record) | High | 7.3 | Microsoft Excel Security Feature Bypass Vulnerability | Aug 9, 2022 |
| CVE-2022-30197(opens NVD record) | Medium | 5.5 | Windows Kernel Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-30194(opens NVD record) | High | 7.5 | Windows WebBrowser Control Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-30176(opens NVD record) | High | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-30175(opens NVD record) | High | 7.8 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-30144(opens NVD record) | High | 7.5 | Windows Bluetooth Service Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-30134(opens NVD record) | Medium | 6.5 | Microsoft Exchange Server Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-30133(opens NVD record) | Critical | 9.8 | Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | Aug 9, 2022 |
| CVE-2022-24516(opens NVD record) | High | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-24477(opens NVD record) | High | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-21980(opens NVD record) | High | 8.0 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Aug 9, 2022 |
| CVE-2022-21979(opens NVD record) | Medium | 4.8 | Microsoft Exchange Server Information Disclosure Vulnerability | Aug 9, 2022 |
| CVE-2022-35493(opens NVD record) | Medium | 6.1 | A Cross-site scripting (XSS) vulnerability in json search parse and the json response in wrteam.in, eShop - Multipurpose Ecommerce Store Website version 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the get_products?search parameter. | Aug 8, 2022 |
| CVE-2022-26979(opens NVD record) | High | 7.5 | Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. | Aug 6, 2022 |
| CVE-2022-27944(opens NVD record) | High | 7.5 | Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference. | Aug 6, 2022 |
| CVE-2022-31618(opens NVD record) | Medium | 5.5 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can dereference a null pointer, which may lead to denial of service. | Aug 5, 2022 |
| CVE-2022-31614(opens NVD record) | High | 7.0 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities to cause denial of service, code execution, and information disclosure. | Aug 5, 2022 |
| CVE-2022-31609(opens NVD record) | High | 7.8 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure. | Aug 5, 2022 |
| CVE-2022-22299(opens NVD record) | High | 7.8 | A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1.1.0 through 1.1.6, FortiProxy version 1.2.0 through 1.2.13, FortiProxy version 2.0.0 through 2.0.7, FortiProxy version 7.0.0 through 7.0.1, FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.2, FortiMail version 6.4.0 through 6.4.5, FortiMail version 7.0.0 through 7.0.2 may allow an authenticated user to execute unauthorized code or commands via specially crafted command arguments. | Aug 5, 2022 |
| CVE-2022-2668(opens NVD record) | High | 7.2 | An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled | Aug 5, 2022 |
| CVE-2022-29071(opens NVD record) | Medium | 4.0 | This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs. The impact of this vulnerability is that the CVP user login passwords might be leaked to other authenticated users. | Aug 5, 2022 |
| CVE-2022-28880(opens NVD record) | Medium | 4.3 | A Denial-of-Service vulnerability was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files it is possible that can crash the scanning engine. The exploit can be triggered remotely by an attacker. | Aug 5, 2022 |
| CVE-2022-27535(opens NVD record) | High | 7.8 | Kaspersky VPN Secure Connection for Windows version up to 21.5 was vulnerable to arbitrary file deletion via abuse of its 'Delete All Service Data And Reports' feature by the local authenticated attacker. | Aug 5, 2022 |
| CVE-2022-1973(opens NVD record) | High | 7.1 | A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem. | Aug 5, 2022 |
| CVE-2022-1158(opens NVD record) | High | 7.8 | A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivileged local users on the host to write outside the userspace region and potentially corrupt the kernel, resulting in a denial of service condition. | Aug 5, 2022 |
| CVE-2021-28511(opens NVD record) | Medium | 5.8 | This advisory documents the impact of an internally found vulnerability in Arista EOS for security ACL bypass. The impact of this vulnerability is that the security ACL drop rule might be bypassed if a NAT ACL rule filter with permit action matches the packet flow. This could allow a host with an IP address in a range that matches the range allowed by a NAT ACL and a range denied by a Security ACL to be forwarded incorrectly as it should have been denied by the Security ACL. This can enable an ACL bypass. | Aug 5, 2022 |
| CVE-2022-31665(opens NVD record) | High | 7.2 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A malicious actor with administrator and network access can trigger a remote code execution. | Aug 5, 2022 |
| CVE-2022-31664(opens NVD record) | High | 7.8 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | Aug 5, 2022 |
| CVE-2022-31663(opens NVD record) | Medium | 6.1 | VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | Aug 5, 2022 |
| CVE-2022-31662(opens NVD record) | High | 7.5 | VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. | Aug 5, 2022 |