87,929 indexed

CVECVE vulnerabilities

87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.

Showing 701–750 of 1,734 in KEV · page 15 of 35

IDTitleSummary
CVE-2022-41352Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
KEVCVSS 9.8Synacor
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to upload arbitrary files using cpio package to gain incorrect access to any other user accounts.
CVE-2022-4135Google Chromium GPU Heap Buffer Overflow Vulnerability
KEVCVSS 9.6Google
Google Chromium GPU contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perfo…
CVE-2022-41328Fortinet FortiOS Path Traversal Vulnerability
KEVFortinet
Fortinet FortiOS contains a path traversal vulnerability that may allow a local privileged attacker to read and write files via crafted CLI commands.
CVE-2022-41223Mitel MiVoice Connect Code Injection Vulnerability
KEVCVSS 6.8Mitel
The Director component in Mitel MiVoice Connect allows an authenticated attacker with internal network access to execute code within the context of the applica…
CVE-2022-41128Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
CVE-2022-41125Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level …
CVE-2022-41091Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
KEVCVSS 5.4Microsoft
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security…
CVE-2022-41082Microsoft Exchange Server Remote Code Execution Vulnerability
KEVCVSS 8.0Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability…
CVE-2022-41080Microsoft Exchange Server Privilege Escalation Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, whic…
CVE-2022-41073Microsoft Windows Print Spooler Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
CVE-2022-41049Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
KEVCVSS 5.4Microsoft
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security…
CVE-2022-41040Microsoft Exchange Server Server-Side Request Forgery Vulnerability
KEVCVSS 8.8Microsoft
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for …
CVE-2022-41033Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-40799D-Link DNR-322L Download of Code Without Integrity Check Vulnerability
KEVCVSS 8.8D-Link
D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on th…
CVE-2022-40765Mitel MiVoice Connect Command Injection Vulnerability
KEVCVSS 6.8Mitel
The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the…
CVE-2022-40684Fortinet Multiple Products Authentication Bypass Vulnerability
KEVCVSS 9.8Fortinet
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform ope…
CVE-2022-40139Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
KEVCVSS 7.2Trend Micro
Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
CVE-2022-39197Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability
KEVFortra
Fortra Cobalt Strike contains a cross-site scripting (XSS) vulnerability in Teamserver that would allow an attacker to set a malformed username in the Beacon c…
CVE-2022-38181Arm Mali GPU Kernel Driver Use-After-Free Vulnerability
KEVArm
Arm Mali GPU Kernel Driver contains a use-after-free vulnerability that may allow a non-privileged user to gain root privilege and/or disclose information.
CVE-2022-38028Microsoft Windows Print Spooler Privilege Escalation Vulnerability
KEVMicrosoft
Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with…
CVE-2022-37969Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
KEVCVSS 7.8Microsoft
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
CVE-2022-3723Google Chromium V8 Type Confusion Vulnerability
KEVGoogle
Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.…
CVE-2022-37055D-Link Routers Buffer Overflow Vulnerability
KEVD-Link
D-Link Routers contains a buffer overflow vulnerability that has a high impact on confidentiality, integrity, and availability. The impacted products could be …
CVE-2022-37042Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability
KEVCVSS 9.8Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-…
CVE-2022-36804Atlassian Bitbucket Server and Data Center Command Injection Vulnerability
KEVAtlassian
Multiple API endpoints of Atlassian Bitbucket Server and Data Center contain a command injection vulnerability where an attacker with access to a public Bitbuc…
CVE-2022-36537ZK Framework AuUploader Unspecified Vulnerability
KEVZK Framework
ZK Framework AuUploader servlets contain an unspecified vulnerability that could allow an attacker to retrieve the content of a file located in the web context…
CVE-2022-35914Teclib GLPI Remote Code Execution Vulnerability
KEVTeclib
Teclib GLPI contains a remote code execution vulnerability in the third-party library, htmlawed.
CVE-2022-35405Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
KEVZoho
Zoho ManageEngine PAM360, Password Manager Pro, and Access Manager Plus contain an unspecified vulnerability that allows for remote code execution.
CVE-2022-34713Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
KEVMicrosoft
A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.
CVE-2022-33891Apache Spark Command Injection Vulnerability
KEVApache
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CVE-2022-32917Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability
KEVApple
Apple kernel, which is included in iOS, iPadOS, and macOS, contains an unspecified vulnerability where an application may be able to execute code with kernel p…
CVE-2022-32894Apple iOS and macOS Out-of-Bounds Write Vulnerability
KEVApple
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.
CVE-2022-32893Apple iOS and macOS Out-of-Bounds Write Vulnerability
KEVApple
Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.
CVE-2022-3236Sophos Firewall Code Injection Vulnerability
KEVSophos
A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
CVE-2022-31199Netwrix Auditor Insecure Object Deserialization Vulnerability
KEVNetwrix
Netwrix Auditor User Activity Video Recording component contains an insecure objection deserialization vulnerability that allows an unauthenticated, remote att…
CVE-2022-3075Google Chromium Mojo Insufficient Data Validation Vulnerability
KEVGoogle
Google Chromium Mojo contains an insufficient data validation vulnerability that allows a remote attacker, who has compromised the renderer process, to potenti…
CVE-2022-30525Zyxel Multiple Firewalls OS Command Injection Vulnerability
KEVZyxel
A command injection vulnerability in the CGI program of some Zyxel firewall versions could allow an attacker to modify specific files and then execute some OS …
CVE-2022-3038Google Chromium Network Service Use-After-Free Vulnerability
KEVGoogle
Google Chromium Network Service contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML…
CVE-2022-30333RARLAB UnRAR Directory Traversal Vulnerability
KEVCVSS 7.5RARLAB
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
CVE-2022-30190Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
KEVCVSS 7.8Microsoft
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully e…
CVE-2022-29499Mitel MiVoice Connect Data Validation Vulnerability
KEVCVSS 9.8Mitel
The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation.
CVE-2022-29464WSO2 Multiple Products Unrestrictive Upload of File Vulnerability
KEVWSO2
Multiple WSO2 products allow for unrestricted file upload, resulting in remote code execution.
CVE-2022-29303SolarView Compact Command Injection Vulnerability
KEVSolarView
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web serv…
CVE-2022-28810Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability
KEVZoho
Zoho ManageEngine ADSelfService Plus contains an unspecified vulnerability allowing for remote code execution when performing a password change or reset.
CVE-2022-2856Google Chromium Intents Insufficient Input Validation Vulnerability
KEVGoogle
Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via…
CVE-2022-27926Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
KEVSynacor
Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability by allowing an endpoint URL to accept parameters without sanitizing.
CVE-2022-27925Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability
KEVCVSS 7.2Synacor
Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform…
CVE-2022-27924Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability
KEVCVSS 7.5Synacor
Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached …
CVE-2022-27593QNAP Photo Station Externally Controlled Reference Vulnerability
KEVQNAP
Certain QNAP NAS running Photo Station with internet exposure contain an externally controlled reference to a resource vulnerability which can allow an attacke…
CVE-2022-27518Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability
KEVCitrix
Citrix Application Delivery Controller (ADC) and Gateway, when configured with SAML SP or IdP configuration, contain an authentication bypass vulnerability tha…
Sourced from NVD + CISA KEV + FIRST EPSS. Curated by Adam Lundqvist, Founder at SQUR.