Search
CVE Explorer
Search the full tracked CVE corpus across every vendor — by keyword, vendor, severity, CVSS band and publication date. Server-rendered; each filtered view has its own URL.
01
Filters
Submit to refine — state is held in the URL.
02
Results
73,094 matching · page 1410/1462Each CVE id links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2022-23296(opens NVD record) | High | 7.8 | Windows Installer Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23295(opens NVD record) | High | 7.8 | Raw Image Extension Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-23294(opens NVD record) | High | 8.8 | Windows Event Tracing Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-23293(opens NVD record) | High | 7.8 | Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23291(opens NVD record) | High | 7.8 | Windows DWM Core Library Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23290(opens NVD record) | High | 7.8 | Windows Inking COM Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23288(opens NVD record) | High | 7.0 | Windows DWM Core Library Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23287(opens NVD record) | High | 7.0 | Windows ALPC Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23286(opens NVD record) | High | 7.0 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23285(opens NVD record) | High | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-23284(opens NVD record) | High | 7.2 | Windows Print Spooler Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23283(opens NVD record) | High | 7.0 | Windows ALPC Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23282(opens NVD record) | High | 7.8 | Paint 3D Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-23281(opens NVD record) | Medium | 5.5 | Windows Common Log File System Driver Information Disclosure Vulnerability | Mar 9, 2022 |
| CVE-2022-23278(opens NVD record) | Medium | 5.9 | Microsoft Defender for Endpoint Spoofing Vulnerability | Mar 9, 2022 |
| CVE-2022-23277(opens NVD record) | High | 8.8 | Microsoft Exchange Server Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-23266(opens NVD record) | High | 7.8 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-23265(opens NVD record) | High | 7.2 | Microsoft Defender for IoT Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-23253(opens NVD record) | Medium | 6.5 | Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | Mar 9, 2022 |
| CVE-2022-22010(opens NVD record) | Medium | 4.4 | Media Foundation Information Disclosure Vulnerability | Mar 9, 2022 |
| CVE-2022-22007(opens NVD record) | High | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-22006(opens NVD record) | High | 7.8 | HEVC Video Extensions Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-21990(opens NVD record) | High | 8.8 | Remote Desktop Client Remote Code Execution Vulnerability | Mar 9, 2022 |
| CVE-2022-21977(opens NVD record) | Low | 3.3 | Media Foundation Information Disclosure Vulnerability | Mar 9, 2022 |
| CVE-2022-21975(opens NVD record) | Medium | 4.7 | Windows Hyper-V Denial of Service Vulnerability | Mar 9, 2022 |
| CVE-2022-21973(opens NVD record) | Medium | 5.5 | Windows Media Center Update Denial of Service Vulnerability | Mar 9, 2022 |
| CVE-2022-21967(opens NVD record) | High | 7.0 | Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability | Mar 9, 2022 |
| CVE-2022-26337(opens NVD record) | High | 7.8 | Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine. | Mar 8, 2022 |
| CVE-2022-26319(opens NVD record) | Medium | 6.5 | An installer search patch element vulnerability in Trend Micro Portable Security 3.0 Pro, 3.0 and 2.0 could allow a local attacker to place an arbitrarily generated DLL file in an installer folder to elevate local privileges. Please note: an attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. | Mar 8, 2022 |
| CVE-2021-36809(opens NVD record) | Medium | 6.1 | A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial of service and data loss, in all versions of Sophos SSL VPN client. | Mar 8, 2022 |
| CVE-2022-22351(opens NVD record) | High | 8.6 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged trusted host user to exploit a vulnerability in the nimsh daemon to cause a denial of service in the nimsh daemon on another trusted host. IBM X-Force ID: 220396 | Mar 7, 2022 |
| CVE-2021-38989(opens NVD record) | Medium | 5.5 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212951. | Mar 7, 2022 |
| CVE-2021-38988(opens NVD record) | Medium | 5.5 | IBM AIX 7.1, 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the AIX kernel to cause a denial of service. IBM X-Force ID: 212950. | Mar 7, 2022 |
| CVE-2022-26490(opens NVD record) | High | 7.8 | st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters. | Mar 6, 2022 |
| CVE-2022-24921(opens NVD record) | High | 7.5 | regexp.Compile in Go before 1.16.15 and 1.17.x before 1.17.8 allows stack exhaustion via a deeply nested expression. | Mar 5, 2022 |
| CVE-2021-43590(opens NVD record) | Medium | 6.0 | Dell EMC Enterprise Storage Analytics for vRealize Operations, versions 4.0.1 to 6.2.1, contain a Plain-text password storage vulnerability. A local high privileged malicious user may potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account. | Mar 4, 2022 |
| CVE-2021-3737(opens NVD record) | High | 7.5 | A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability. | Mar 4, 2022 |
| CVE-2021-3656(opens NVD record) | High | 8.8 | A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape. | Mar 4, 2022 |
| CVE-2022-26318(opens NVD record) | Critical | 9.8 | On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2. | Mar 4, 2022 |
| CVE-2022-23233(opens NVD record) | High | 7.5 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could lead to Denial of Service (DoS) of the Local Distribution Router (LDR) service. | Mar 4, 2022 |
| CVE-2022-23232(opens NVD record) | Medium | 4.9 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.6.0 are susceptible to a vulnerability which when successfully exploited could allow disabled, expired, or locked external user accounts to access S3 data to which they previously had access. StorageGRID 11.6.0 obtains the user account status from Active Directory or Azure and will block S3 access for disabled user accounts during the subsequent background synchronization. User accounts that are expired or locked for Active Directory or Azure, or user accounts that are disabled, expired, or locked in identity sources other than Active Directory or Azure must be manually removed from group memberships or have their S3 keys manually removed from Tenant Manager in all versions of StorageGRID (formerly StorageGRID Webscale). | Mar 4, 2022 |
| CVE-2021-3575(opens NVD record) | High | 7.8 | A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg. | Mar 4, 2022 |
| CVE-2021-20319(opens NVD record) | High | 7.8 | An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary data, and achieve full access to the node being installed. | Mar 4, 2022 |
| CVE-2022-21828(opens NVD record) | High | 7.2 | A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and 1.35.3. | Mar 4, 2022 |
| CVE-2022-26336(opens NVD record) | Medium | 5.5 | A shortcoming in the HMEF package of poi-scratchpad (Apache POI) allows an attacker to cause an Out of Memory exception. This package is used to read TNEF files (Microsoft Outlook and Microsoft Exchange Server). If an application uses poi-scratchpad to parse TNEF files and the application allows untrusted users to supply them, then a carefully crafted file can cause an Out of Memory exception. This issue affects poi-scratchpad version 5.2.0 and prior versions. Users are recommended to upgrade to poi-scratchpad 5.2.1. | Mar 4, 2022 |
| CVE-2022-22946(opens NVD record) | Medium | 5.5 | In spring cloud gateway versions prior to 3.1.1+ , applications that are configured to enable HTTP2 and no key store or trusted certificates are set will be configured to use an insecure TrustManager. This makes the gateway able to connect to remote services with invalid or custom certificates. | Mar 4, 2022 |
| CVE-2021-3744(opens NVD record) | Medium | 5.5 | A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is similar with the older CVE-2019-18808. | Mar 4, 2022 |
| CVE-2021-3743(opens NVD record) | High | 7.1 | An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability. | Mar 4, 2022 |
| CVE-2021-23214(opens NVD record) | High | 8.1 | When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption. | Mar 4, 2022 |
| CVE-2022-0839(opens NVD record) | Critical | 9.8 | Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. | Mar 4, 2022 |