Vulnerability index

Browse CVEs

1,646 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-26485 KEVEPSS 14% Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing thi… Firefox 91.6.1 / 91.6.2+ Fix from $1,9502022-12-22 HIGH 8.8 CVE-2022-42856 KEVEPSS 9% A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 16.2, tvOS 16.2, macOS Ventura 13.1, iOS 15.7.2 and … Safari 13.1 / 15.7.2+ Fix from $1,9502022-12-15 MEDIUM 5.4 CVE-2022-44698 KEVEPSS 76% Windows SmartScreen Security Feature Bypass Vulnerability Windows 10 1607 10.0.14393.5582 / 10.0.17763.3770+ Fix from $1,6002022-12-13 CRITICAL 9.8 CVE-2022-27518 KEVEPSS 7% Unauthenticated remote arbitrary code execution Application Delivery Controller Firmware 12.1-55.291 / 12.1-65.25+ Fix from $2,3002022-12-13 CRITICAL 9.8 CVE-2022-46169 KEVEPSS 100% Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected … Cacti 1.2.23+ Fix from $2,3002022-12-05 HIGH 8.8 CVE-2022-4262 KEVEPSS 15% Type confusion in V8 in Google Chrome prior to 108.0.5359.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… Chrome 108.0.5359.94+ Fix from $1,9502022-12-02 HIGH 8.8 CVE-2022-40799 KEVEPSS 32% Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated attacker to execute OS level commands on the device. Dnr 322l Firmware after 2.60b15 Fix from $1,9502022-11-29 CRITICAL 9.6 CVE-2022-4135 KEVEPSS 32% Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentiall… Chrome 107.0.1418.62 / 107.0.5304.121+ Fix from $2,3002022-11-25 MEDIUM 6.8 CVE-2022-41223 KEVEPSS 11% The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection atta… Mivoice Connect after 22.22.6100.0 Fix from $1,6002022-11-22 MEDIUM 6.8 CVE-2022-40765 KEVEPSS 10% A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with interna… Mivoice Connect after 22.22.6100.0 Fix from $1,6002022-11-22 HIGH 7.8 CVE-2022-23748 KEVEPSS 9% mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what cond… Dante Application Library after 1.2.0 Fix from $1,9502022-11-17 HIGH 8.8 CVE-2022-41128 KEVEPSS 25% Windows Scripting Languages Remote Code Execution Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,9502022-11-09 HIGH 7.8 CVE-2022-41125 KEV Windows CNG Key Isolation Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,9502022-11-09 MEDIUM 5.4 CVE-2022-41091 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,6002022-11-09 HIGH 8.8 CVE-2022-41080 KEVEPSS 77% Microsoft Exchange Server Elevation of Privilege Vulnerability Exchange Server Patch available Fix from $1,9502022-11-09 HIGH 7.8 CVE-2022-41073 KEV Windows Print Spooler Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,9502022-11-09 MEDIUM 5.4 CVE-2022-41049 KEV Windows Mark of the Web Security Feature Bypass Vulnerability Windows 10 1507 10.0.10240.19567 / 10.0.14393.5501+ Fix from $1,6002022-11-09 CRITICAL 9.8 CVE-2022-31199 KEVEPSS 36% Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server … Auditor 10.5+ Fix from $2,3002022-11-08 HIGH 8.8 CVE-2022-3723 KEVEPSS 8% Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page… Chrome 107.0.5304.87+ Fix from $1,9502022-11-01 HIGH 7.8 CVE-2022-42827 KEV An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 16.1 and iPadOS 16… Ipados 15.7.1 / 16.1+ Fix from $1,9502022-11-01 HIGH 8.8 CVE-2022-38181 KEVEPSS 13% The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0… Bifrost Gpu Kernel Driver Mitigation only Fix from $1,9502022-10-25 CRITICAL 9.8 CVE-2016-20017 KEVEPSS 65% D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wild in 2016… Dsl 2750b Firmware 1.05+ Fix from $2,3002022-10-19 CRITICAL 9.8 CVE-2022-21587 KEVEPSS 98% Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are a… E Business Suite after 12.2.11 Fix from $2,3002022-10-18 CRITICAL 9.8 CVE-2022-40684 KEVEPSS 100% An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiP… Fortiproxy 7.0.7 / 7.2.2+ Fix from $2,3002022-10-18 HIGH 7.8 CVE-2022-41033 KEV Windows COM+ Event System Service Elevation of Privilege Vulnerability Windows 10 1507 10.0.10240.19507 / 10.0.14393.5427+ Fix from $1,9502022-10-11 HIGH 7.8 CVE-2022-38028 KEVEPSS 15% Windows Print Spooler Elevation of Privilege Vulnerability Windows 10 1507 6.3.9600.20625 / 10.0.10240.19507+ Fix from $1,9502022-10-11 HIGH 8.0 CVE-2022-41082 KEVEPSS 100% Microsoft Exchange Server Remote Code Execution Vulnerability Exchange Server Patch available Fix from $1,9502022-10-03 HIGH 8.8 CVE-2022-41040 KEVEPSS 100% Microsoft Exchange Server Elevation of Privilege Vulnerability Exchange Server Patch available Fix from $1,9502022-10-03 HIGH 7.8 CVE-2022-20775 KEVEPSS 12% A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability i… Catalyst Sd Wan Manager 20.6.3 / 20.7.2+ Fix from $1,9502022-09-30 CRITICAL 9.6 CVE-2022-3075 KEVEPSS 6% Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to p… Chrome 105.0.5195.102+ Fix from $2,3002022-09-26