87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 701–750 of 1,734 in KEV · page 15 of 35
| ID | Title | Summary |
|---|---|---|
| CVE-2022-41352 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability KEVCVSS 9.8Synacor | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts. |
| CVE-2022-4135 | Google Chromium GPU Heap Buffer Overflow Vulnerability KEVCVSS 9.6Google | Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perfo… |
| CVE-2022-41328 | Fortinet FortiOS Path Traversal Vulnerability KEVFortinet | Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands. |
| CVE-2022-41223 | Mitel MiVoice Connect Code Injection Vulnerability KEVCVSS 6.8Mitel | The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the applica… |
| CVE-2022-41128 | Microsoft Windows Scripting Languages Remote Code Execution Vulnerability KEVCVSS 8.8Microsoft | Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. |
| CVE-2022-41125 | Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level … |
| CVE-2022-41091 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability KEVCVSS 5.4Microsoft | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security… |
| CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability KEVCVSS 8.0Microsoft | Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability… |
| CVE-2022-41080 | Microsoft Exchange Server Privilege Escalation Vulnerability KEVCVSS 8.8Microsoft | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, whic… |
| CVE-2022-41073 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges. |
| CVE-2022-41049 | Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability KEVCVSS 5.4Microsoft | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security… |
| CVE-2022-41040 | Microsoft Exchange Server Server-Side Request Forgery Vulnerability KEVCVSS 8.8Microsoft | Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for … |
| CVE-2022-41033 | Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2022-40799 | D-Link DNR-322L Download of Code Without Integrity Check Vulnerability KEVCVSS 8.8D-Link | D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on th… |
| CVE-2022-40765 | Mitel MiVoice Connect Command Injection Vulnerability KEVCVSS 6.8Mitel | The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the… |
| CVE-2022-40684 | Fortinet Multiple Products Authentication Bypass Vulnerability KEVCVSS 9.8Fortinet | Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform ope… |
| CVE-2022-40139 | Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability KEVCVSS 7.2Trend Micro | Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution. |
| CVE-2022-39197 | Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability KEVFortra | Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon c… |
| CVE-2022-38181 | Arm Mali GPU Kernel Driver Use-After-Free Vulnerability KEVArm | Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information. |
| CVE-2022-38028 | Microsoft Windows Print Spooler Privilege Escalation Vulnerability KEVMicrosoft | Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with… |
| CVE-2022-37969 | Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability KEVCVSS 7.8Microsoft | Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation. |
| CVE-2022-3723 | Google Chromium V8 Type Confusion Vulnerability KEVGoogle | Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2022-37055 | D-Link Routers Buffer Overflow Vulnerability KEVD-Link | D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be … |
| CVE-2022-37042 | Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability KEVCVSS 9.8Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-… |
| CVE-2022-36804 | Atlassian Bitbucket Server and Data Center Command Injection Vulnerability KEVAtlassian | Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbuc… |
| CVE-2022-36537 | ZK Framework AuUploader Unspecified Vulnerability KEVZK Framework | ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context… |
| CVE-2022-35914 | Teclib GLPI Remote Code Execution Vulnerability KEVTeclib | Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed. |
| CVE-2022-35405 | Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability KEVZoho | Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution. |
| CVE-2022-34713 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability KEVMicrosoft | A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application. |
| CVE-2022-33891 | Apache Spark Command Injection Vulnerability KEVApache | Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled. |
| CVE-2022-32917 | Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability KEVApple | Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel p… |
| CVE-2022-32894 | Apple iOS and macOS Out-of-Bounds Write Vulnerability KEVApple | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. |
| CVE-2022-32893 | Apple iOS and macOS Out-of-Bounds Write Vulnerability KEVApple | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content. |
| CVE-2022-3236 | Sophos Firewall Code Injection Vulnerability KEVSophos | A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution. |
| CVE-2022-31199 | Netwrix Auditor Insecure Object Deserialization Vulnerability KEVNetwrix | Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote att… |
| CVE-2022-3075 | Google Chromium Mojo Insufficient Data Validation Vulnerability KEVGoogle | Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potenti… |
| CVE-2022-30525 | Zyxel Multiple Firewalls OS Command Injection Vulnerability KEVZyxel | A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS … |
| CVE-2022-3038 | Google Chromium Network Service Use-After-Free Vulnerability KEVGoogle | Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML… |
| CVE-2022-30333 | RARLAB UnRAR Directory Traversal Vulnerability KEVCVSS 7.5RARLAB | RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. |
| CVE-2022-30190 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability KEVCVSS 7.8Microsoft | A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e… |
| CVE-2022-29499 | Mitel MiVoice Connect Data Validation Vulnerability KEVCVSS 9.8Mitel | The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. |
| CVE-2022-29464 | WSO2 Multiple Products Unrestrictive Upload of File Vulnerability KEVWSO2 | Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution. |
| CVE-2022-29303 | SolarView Compact Command Injection Vulnerability KEVSolarView | SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web serv… |
| CVE-2022-28810 | Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability KEVZoho | Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset. |
| CVE-2022-2856 | Google Chromium Intents Insufficient Input Validation Vulnerability KEVGoogle | Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via… |
| CVE-2022-27926 | Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability KEVSynacor | Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing. |
| CVE-2022-27925 | Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability KEVCVSS 7.2Synacor | Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform… |
| CVE-2022-27924 | Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability KEVCVSS 7.5Synacor | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached … |
| CVE-2022-27593 | QNAP Photo Station Externally Controlled Reference Vulnerability KEVQNAP | Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacke… |
| CVE-2022-27518 | Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability KEVCitrix | Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability tha… |