Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
72,624 matching · page 1377/1453Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-23279(opens NVD record) | High | 7.0 | Windows ALPC Elevation of Privilege Vulnerability | May 10, 2022 |
| CVE-2022-23270(opens NVD record) | High | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-23267(opens NVD record) | High | 7.5 | .NET and Visual Studio Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-22713(opens NVD record) | Medium | 5.6 | Windows Hyper-V Denial of Service Vulnerability | May 10, 2022 |
| CVE-2022-22019(opens NVD record) | High | 8.8 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-22017(opens NVD record) | High | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-22016(opens NVD record) | High | 7.0 | Windows PlayToManager Elevation of Privilege Vulnerability | May 10, 2022 |
| CVE-2022-22015(opens NVD record) | Medium | 6.5 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | May 10, 2022 |
| CVE-2022-22014(opens NVD record) | High | 8.8 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-22013(opens NVD record) | High | 8.8 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-22012(opens NVD record) | Critical | 9.8 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-22011(opens NVD record) | Medium | 5.5 | Windows Graphics Component Information Disclosure Vulnerability | May 10, 2022 |
| CVE-2022-21978(opens NVD record) | High | 8.2 | Microsoft Exchange Server Elevation of Privilege Vulnerability | May 10, 2022 |
| CVE-2022-21972(opens NVD record) | High | 8.1 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | May 10, 2022 |
| CVE-2022-0866(opens NVD record) | Medium | 5.3 | This is a concurrency issue that can result in the wrong caller principal being returned from the session context of an EJB that is configured with a RunAs principal. In particular, the org.jboss.as.ejb3.component.EJBComponent class has an incomingRunAsIdentity field. This field is used by the org.jboss.as.ejb3.security.RunAsPrincipalInterceptor to keep track of the current identity prior to switching to a new identity created using the RunAs principal. The exploit consist that the EJBComponent#incomingRunAsIdentity field is currently just a SecurityIdentity. This means in a concurrent environment, where multiple users are repeatedly invoking an EJB that is configured with a RunAs principal, it's possible for the wrong the caller principal to be returned from EJBComponent#getCallerPrincipal. Similarly, it's also possible for EJBComponent#isCallerInRole to return the wrong value. Both of these methods rely on incomingRunAsIdentity. Affects all versions of JBoss EAP from 7.1.0 and all versions of WildFly 11+ when Elytron is enabled. | May 10, 2022 |
| CVE-2022-28986(opens NVD record) | High | 7.5 | LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts. | May 10, 2022 |
| CVE-2022-23677(opens NVD record) | High | 8.1 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities. | May 10, 2022 |
| CVE-2022-23676(opens NVD record) | Critical | 9.8 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions; ArubaOS-Switch 16.04.xxxx: All versions; ArubaOS-Switch 16.05.xxxx: All versions; ArubaOS-Switch 16.06.xxxx: All versions; ArubaOS-Switch 16.07.xxxx: All versions; ArubaOS-Switch 16.08.xxxx: KB/WB/WC/YA/YB/YC.16.08.0024 and below; ArubaOS-Switch 16.09.xxxx: KB/WB/WC/YA/YB/YC.16.09.0019 and below; ArubaOS-Switch 16.10.xxxx: KB/WB/WC/YA/YB/YC.16.10.0019 and below; ArubaOS-Switch 16.11.xxxx: KB/WB/WC/YA/YB/YC.16.11.0003 and below. Aruba has released upgrades for ArubaOS-Switch Devices that address these security vulnerabilities. | May 10, 2022 |
| CVE-2022-22454(opens NVD record) | High | 7.8 | IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | May 10, 2022 |
| CVE-2021-39024(opens NVD record) | Medium | 6.1 | IBM Guardium Data Encryption (GDE) 4.0.0.0 and 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 213862. | May 10, 2022 |
| CVE-2022-26988(opens NVD record) | High | 7.8 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MntAte` function. Local users could get remote code execution. | May 10, 2022 |
| CVE-2022-26987(opens NVD record) | High | 7.8 | TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution. | May 10, 2022 |
| CVE-2022-23704(opens NVD record) | High | 7.5 | A potential security vulnerability has been identified in Integrated Lights-Out 4 (iLO 4). The vulnerability could allow remote Denial of Service. The vulnerability is resolved in Integrated Lights-Out 4 (iLO 4) 2.80 and later. | May 9, 2022 |
| CVE-2021-43712(opens NVD record) | Medium | 5.4 | Stored XSS in Add New Employee Form in Sourcecodester Employee Daily Task Management System 1.0 Allows Remote Attacker to Inject/Store Arbitrary Code via the Name Field. | May 9, 2022 |
| CVE-2022-28162(opens NVD record) | Low | 3.3 | Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text. | May 9, 2022 |
| CVE-2022-28161(opens NVD record) | Medium | 5.5 | An information exposure through log file vulnerability in Brocade SANNav versions before Brocade SANnav 2.2.0 could allow an authenticated, local attacker to view sensitive information such as ssh passwords in filetansfer.log in debug mode. To exploit this vulnerability, the attacker would need to have valid user credentials and turn on debug mode. | May 9, 2022 |
| CVE-2022-22481(opens NVD record) | Medium | 5.3 | IBM Navigator for i 7.2, 7.3, and 7.4 (heritage version) could allow a remote attacker to obtain access to the web interface without valid credentials. By modifying the sign on request, an attacker can gain visibility to the fully qualified domain name of the target system and the navigator tasks page, however they do not gain the ability to perform those tasks on the system or see any specific system data. IBM X-Force ID: 225899. | May 9, 2022 |
| CVE-2022-22319(opens NVD record) | Medium | 5.4 | IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. | May 9, 2022 |
| CVE-2021-20479(opens NVD record) | High | 7.5 | IBM Cloud Pak System 2.3.0 through 2.3.3.3 Interim Fix 1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 197498. | May 9, 2022 |
| CVE-2022-30333(opens NVD record) | High | 7.5 | RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. | May 9, 2022 |
| CVE-2022-1619(opens NVD record) | High | 7.8 | Heap-based Buffer Overflow in function cmdline_erase_chars in GitHub repository vim/vim prior to 8.2.4899. This vulnerabilities are capable of crashing software, modify memory, and possible remote execution | May 8, 2022 |
| CVE-2022-28279(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28278(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28277(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file. | May 6, 2022 |
| CVE-2022-28276(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28275(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28274(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28273(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28272(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28271(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file. | May 6, 2022 |
| CVE-2022-28270(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file. | May 6, 2022 |
| CVE-2022-27784(opens NVD record) | High | 7.8 | Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in After Effects. | May 6, 2022 |
| CVE-2022-27783(opens NVD record) | High | 7.8 | Adobe After Effects versions 22.2.1 (and earlier) and 18.4.5 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted file in After Effects. | May 6, 2022 |
| CVE-2022-24105(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious U3D file. | May 6, 2022 |
| CVE-2022-24099(opens NVD record) | Low | 3.3 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-24098(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX file that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious PCX file. | May 6, 2022 |
| CVE-2022-23205(opens NVD record) | High | 7.8 | Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | May 6, 2022 |
| CVE-2022-28165(opens NVD record) | High | 8.8 | A vulnerability in the role-based access control (RBAC) functionality of the Brocade SANNav before 2.2.0 could allow an authenticated, remote attacker to access resources that they should not be able to access and perform actions that they should not be able to perform. The vulnerability exists because restrictions are not performed on Server side to ensure the user has required permission before processing requests. | May 6, 2022 |
| CVE-2021-42743(opens NVD record) | High | 8.8 | A misconfiguration in the node default path allows for local privilege escalation from a lower privileged user to the Splunk user in Splunk Enterprise versions before 8.1.1 on Windows. | May 6, 2022 |
| CVE-2022-28164(opens NVD record) | Medium | 6.5 | Brocade SANnav before SANnav 2.2.0 application uses the Blowfish symmetric encryption algorithm for the storage of passwords. This could allow an authenticated attacker to decrypt stored account passwords. | May 6, 2022 |