Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,094 matching · page 1402/1462Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-26908(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 5, 2022 |
| CVE-2022-26900(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 5, 2022 |
| CVE-2022-26895(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 5, 2022 |
| CVE-2022-26894(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 5, 2022 |
| CVE-2022-26891(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 5, 2022 |
| CVE-2022-24523(opens NVD record) | Medium | 4.3 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Apr 5, 2022 |
| CVE-2022-24475(opens NVD record) | High | 8.3 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Apr 5, 2022 |
| CVE-2022-28219(opens NVD record) | Critical | 9.8 | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. | Apr 5, 2022 |
| CVE-2022-25373(opens NVD record) | Medium | 5.4 | Zoho ManageEngine SupportCenter Plus before 11020 allows Stored XSS in the request history. | Apr 5, 2022 |
| CVE-2022-25245(opens NVD record) | Medium | 5.3 | Zoho ManageEngine ServiceDesk Plus before 13001 allows anyone to know the organisation's default currency name. | Apr 5, 2022 |
| CVE-2022-24978(opens NVD record) | High | 8.8 | Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response. | Apr 5, 2022 |
| CVE-2022-22356(opens NVD record) | Medium | 6.5 | IBM MQ Appliance 9.2 CD and 9.2 LTS could allow an attacker to enumerate account credentials due to an observable discrepancy in valid and invalid login attempts. IBM X-Force ID: 220487. | Apr 5, 2022 |
| CVE-2022-22355(opens NVD record) | Medium | 5.3 | IBM MQ Appliance 9.2 CD and 9.2 LTS are vulnerable to a denial of service in the Login component of the application which could allow an attacker to cause a drop in performance. | Apr 5, 2022 |
| CVE-2022-23909(opens NVD record) | High | 7.8 | There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file. | Apr 5, 2022 |
| CVE-2022-26281(opens NVD record) | High | 7.5 | BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue. | Apr 5, 2022 |
| CVE-2022-0807(opens NVD record) | Medium | 6.5 | Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0806(opens NVD record) | Medium | 6.5 | Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0805(opens NVD record) | High | 8.8 | Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. | Apr 5, 2022 |
| CVE-2022-0804(opens NVD record) | Medium | 6.5 | Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0803(opens NVD record) | Medium | 6.5 | Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0802(opens NVD record) | Medium | 6.5 | Inappropriate implementation in Full screen mode in Google Chrome on Android prior to 99.0.4844.51 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0799(opens NVD record) | High | 8.8 | Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file. | Apr 5, 2022 |
| CVE-2022-0798(opens NVD record) | High | 8.8 | Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | Apr 5, 2022 |
| CVE-2022-0797(opens NVD record) | High | 8.8 | Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0796(opens NVD record) | High | 8.8 | Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | Apr 5, 2022 |
| CVE-2022-0791(opens NVD record) | High | 8.8 | Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions. | Apr 5, 2022 |
| CVE-2022-27651(opens NVD record) | Medium | 6.8 | A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux process capabilities, enabling an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. This has the potential to impact confidentiality and integrity. | Apr 4, 2022 |
| CVE-2022-27650(opens NVD record) | High | 7.5 | A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. | Apr 4, 2022 |
| CVE-2022-27649(opens NVD record) | High | 7.5 | A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs. | Apr 4, 2022 |
| CVE-2022-27609(opens NVD record) | Medium | 6.0 | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by users with Administrator privileges. This could result in a user disabling Forcepoint One Endpoint and the protection offered by it. | Apr 4, 2022 |
| CVE-2022-27608(opens NVD record) | Medium | 6.0 | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator privileges. This could result in a user disabling anti-tampering mechanisms which would then allow the user to disable Forcepoint One Endpoint and the protection offered by it. | Apr 4, 2022 |
| CVE-2022-23700(opens NVD record) | Medium | 5.5 | A local unauthorized read access to files vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | Apr 4, 2022 |
| CVE-2022-23699(opens NVD record) | High | 7.8 | A local authentication restriction bypass vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | Apr 4, 2022 |
| CVE-2022-23698(opens NVD record) | High | 7.5 | A remote unauthenticated disclosure of information vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | Apr 4, 2022 |
| CVE-2022-23697(opens NVD record) | Medium | 6.1 | A remote cross-site scripting (xss) vulnerability was discovered in HPE OneView version(s): Prior to 6.6. HPE has provided a software update to resolve this vulnerability in HPE OneView. | Apr 4, 2022 |
| CVE-2022-24801(opens NVD record) | High | 8.1 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request constructs more leniently than permitted by RFC 7230. This non-conformant parsing can lead to desync if requests pass through multiple HTTP parsers, potentially resulting in HTTP request smuggling. Users who may be affected use Twisted Web's HTTP 1.1 server and/or proxy and also pass requests through a different HTTP server and/or proxy. The Twisted Web client is not affected. The HTTP 2.0 server uses a different parser, so it is not affected. The issue has been addressed in Twisted 22.4.0rc1. Two workarounds are available: Ensure any vulnerabilities in upstream proxies have been addressed, such as by upgrading them; or filter malformed requests by other means, such as configuration of an upstream proxy. | Apr 4, 2022 |
| CVE-2022-24785(opens NVD record) | High | 7.5 | Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied to all affected versions. As a workaround, sanitize the user-provided locale name before passing it to Moment.js. | Apr 4, 2022 |
| CVE-2021-33616(opens NVD record) | Medium | 5.4 | RSA Archer 6.x through 6.9 SP1 P4 (6.9.1.4) allows stored XSS. | Apr 4, 2022 |
| CVE-2022-28390(opens NVD record) | High | 7.8 | ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. | Apr 3, 2022 |
| CVE-2022-28389(opens NVD record) | Medium | 5.5 | mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. | Apr 3, 2022 |
| CVE-2022-28388(opens NVD record) | Medium | 5.5 | usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. | Apr 3, 2022 |
| CVE-2022-1210(opens NVD record) | Medium | 4.3 | A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used. | Apr 3, 2022 |
| CVE-2022-22965(opens NVD record) | Critical | 9.8 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it. | Apr 1, 2022 |
| CVE-2022-22963(opens NVD record) | Critical | 9.8 | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources. | Apr 1, 2022 |
| CVE-2022-22950(opens NVD record) | Medium | 6.5 | n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. | Apr 1, 2022 |
| CVE-2022-22570(opens NVD record) | Critical | 10.0 | A buffer overflow vulnerability found in the UniFi Door Access Reader Lite’s (UA Lite) firmware (Version 3.8.28.24 and earlier) allows a malicious actor who has gained access to a network to control all connected UA devices. This vulnerability is fixed in Version 3.8.31.13 and later. | Apr 1, 2022 |
| CVE-2021-3461(opens NVD record) | High | 7.1 | A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name]. | Apr 1, 2022 |
| CVE-2021-28504(opens NVD record) | High | 7.5 | On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access-list has a rule which matches on “vxlan” as protocol then that rule and subsequent rules ( rules declared after it in ACL ) do not match on IP protocol field as expected. | Apr 1, 2022 |
| CVE-2021-26623(opens NVD record) | High | 7.8 | A remote code execution vulnerability due to incomplete check for 'xheader_decode_path_record' function's parameter length value in the ark library. Remote attackers can induce exploit malicious code using this function. | Apr 1, 2022 |
| CVE-2021-20238(opens NVD record) | Low | 3.7 | It was found in OpenShift Container Platform 4 that ignition config, served by the Machine Config Server, can be accessed externally from clusters without authentication. The MCS endpoint (port 22623) provides ignition configuration used for bootstrapping Nodes and can include some sensitive data, e.g. registry pull secrets. There are two scenarios where this data can be accessed. The first is on Baremetal, OpenStack, Ovirt, Vsphere and KubeVirt deployments which do not have a separate internal API endpoint and allow access from outside the cluster to port 22623 from the standard OpenShift API Virtual IP address. The second is on cloud deployments when using unsupported network plugins, which do not create iptables rules that prevent to port 22623. In this scenario, the ignition config is exposed to all pods within the cluster and cannot be accessed externally. | Apr 1, 2022 |