Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,155 matching · page 1357/1444Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-30137(opens NVD record) | Medium | 6.7 | Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All Service Fabric and Docker versions are impacted. | Jun 15, 2022 |
| CVE-2022-30136(opens NVD record) | Critical | 9.8 | Windows Network File System Remote Code Execution Vulnerability | Jun 15, 2022 |
| CVE-2022-30135(opens NVD record) | High | 7.8 | Windows Media Center Elevation of Privilege Vulnerability | Jun 15, 2022 |
| CVE-2022-30132(opens NVD record) | High | 7.8 | Windows Container Manager Service Elevation of Privilege Vulnerability | Jun 15, 2022 |
| CVE-2022-30131(opens NVD record) | High | 7.8 | Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | Jun 15, 2022 |
| CVE-2022-29149(opens NVD record) | High | 7.8 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | Jun 15, 2022 |
| CVE-2022-29143(opens NVD record) | High | 7.5 | Microsoft SQL Server Remote Code Execution Vulnerability | Jun 15, 2022 |
| CVE-2022-29119(opens NVD record) | High | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | Jun 15, 2022 |
| CVE-2022-29111(opens NVD record) | High | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | Jun 15, 2022 |
| CVE-2022-22021(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Jun 15, 2022 |
| CVE-2022-22018(opens NVD record) | High | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | Jun 15, 2022 |
| CVE-2022-30669(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-30668(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-30667(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-30666(opens NVD record) | Medium | 5.5 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-30649(opens NVD record) | High | 7.8 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-30648(opens NVD record) | High | 7.8 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-30647(opens NVD record) | High | 7.8 | Adobe Illustrator versions 26.0.2 (and earlier) and 25.4.5 (and earlier) are affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-21166(opens NVD record) | Medium | 5.5 | Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | Jun 15, 2022 |
| CVE-2022-28850(opens NVD record) | Medium | 5.5 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28849(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28848(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28847(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28846(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28845(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28844(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28843(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28842(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by a Use-After-Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28841(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28840(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28839(opens NVD record) | High | 7.8 | Adobe Bridge version 12.0.1 (and earlier versions) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2022-28226(opens NVD record) | High | 7.8 | Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process. | Jun 15, 2022 |
| CVE-2022-28225(opens NVD record) | High | 7.8 | Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process. | Jun 15, 2022 |
| CVE-2022-21125(opens NVD record) | Medium | 5.5 | Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | Jun 15, 2022 |
| CVE-2022-21123(opens NVD record) | Medium | 5.5 | Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | Jun 15, 2022 |
| CVE-2021-43755(opens NVD record) | High | 7.8 | Adobe After Effects versions 22.0 (and earlier) and 18.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | Jun 15, 2022 |
| CVE-2021-42735(opens NVD record) | High | 7.8 | Adobe Photoshop version 22.5.1 (and earlier versions ) is affected by an Access of Memory Location After End of Buffer vulnerability, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | Jun 15, 2022 |
| CVE-2021-25261(opens NVD record) | High | 7.8 | Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process. | Jun 15, 2022 |
| CVE-2021-43756(opens NVD record) | High | 7.8 | Adobe Media Encoder versions 22.0, 15.4.2 (and earlier) are affected by an Out-of-bounds Write vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | Jun 15, 2022 |
| CVE-2021-43754(opens NVD record) | High | 7.8 | Adobe Prelude version 22.1.1 (and earlier) is affected by an Out-of-bounds Write vulnerability due to insecure handling of a malicious file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | Jun 15, 2022 |
| CVE-2021-40776(opens NVD record) | Medium | 6.1 | Adobe Lightroom Classic 10.3 (and earlier) are affected by a privilege escalation vulnerability in the Offline Lightroom Classic installer. An authenticated attacker could leverage this vulnerability to escalate privileges. User interaction is required before product installation to abuse this vulnerability. | Jun 15, 2022 |
| CVE-2022-20825(opens NVD record) | Critical | 9.8 | A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient user input validation of incoming HTTP packets. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on an affected device using root-level privileges. Cisco has not released software updates that address this vulnerability. | Jun 15, 2022 |
| CVE-2022-20819(opens NVD record) | Medium | 6.5 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege levels for sensitive data are not properly enforced. An attacker with read-only privileges for the web-based management interface on an affected device could exploit this vulnerability by browsing to a page that contains sensitive data. A successful exploit could allow the attacker to collect sensitive information about the system configuration. | Jun 15, 2022 |
| CVE-2022-20817(opens NVD record) | High | 7.4 | A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the manufacturing process that could result in duplicated manufactured keys installed on multiple devices. An attacker could exploit this vulnerability by performing a machine-in-the-middle attack on the secure communication between the phone and the CUCM. A successful exploit could allow the attacker to impersonate another user's phone. This vulnerability cannot be addressed with software updates. There is a workaround that addresses this vulnerability. | Jun 15, 2022 |
| CVE-2022-20798(opens NVD record) | Critical | 9.8 | A vulnerability in the external authentication functionality of Cisco Secure Email and Web Manager, formerly known as Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass authentication and log in to the web management interface of an affected device. This vulnerability is due to improper authentication checks when an affected device uses Lightweight Directory Access Protocol (LDAP) for external authentication. An attacker could exploit this vulnerability by entering a specific input on the login page of the affected device. A successful exploit could allow the attacker to gain unauthorized access to the web-based management interface of the affected device. | Jun 15, 2022 |
| CVE-2022-20736(opens NVD record) | Medium | 5.3 | A vulnerability in the web-based management interface of Cisco AppDynamics Controller Software could allow an unauthenticated, remote attacker to access a configuration file and the login page for an administrative console that they would not normally have authorization to access. This vulnerability is due to improper authorization checking for HTTP requests that are submitted to the affected web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected instance of AppDynamics Controller. A successful exploit could allow the attacker to access the login page for an administrative console. AppDynamics has released software updates that address this vulnerability. | Jun 15, 2022 |
| CVE-2022-20733(opens NVD record) | Medium | 5.3 | A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Assertion Markup Language (SAML) metadata. An attacker could exploit this vulnerability by using the exposed SAML metadata to bypass authentication to the user portal. A successful exploit could allow the attacker to access all roles without any restrictions. | Jun 15, 2022 |
| CVE-2022-20664(opens NVD record) | High | 7.7 | A vulnerability in the web management interface of Cisco Secure Email and Web Manager, formerly Cisco Security Management Appliance (SMA), and Cisco Email Security Appliance (ESA) could allow an authenticated, remote attacker to retrieve sensitive information from a Lightweight Directory Access Protocol (LDAP) external authentication server connected to an affected device. This vulnerability is due to a lack of proper input sanitization while querying the external authentication server. An attacker could exploit this vulnerability by sending a crafted query through an external authentication web page. A successful exploit could allow the attacker to gain access to sensitive information, including user credentials from the external authentication server. To exploit this vulnerability, an attacker would need valid operator-level (or higher) credentials. | Jun 15, 2022 |
| CVE-2021-42732(opens NVD record) | High | 7.8 | Access of Memory Location After End of Buffer (CWE-788) | Jun 15, 2022 |
| CVE-2021-40727(opens NVD record) | High | 7.8 | Access of Memory Location After End of Buffer (CWE-788 | Jun 15, 2022 |