Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action |
---|---|---|---|---|---|
CVE-2022-24468 | Azure Site Recovery Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24469 | Azure Site Recovery Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2447 | A flaw was found in Keystone. There is a time lag (up to one hour in a default configuration) between when security policy says a token should be revoked from when it is actually revoked. This could allow a remote administrator to secretly maintain access for longer than expected. | Unknown | N/A | n/a | |
CVE-2022-24470 | Azure Site Recovery Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24471 | Azure Site Recovery Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24472 | Microsoft SharePoint Server Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24473 | Microsoft Excel Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24474 | Windows Win32k Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24475 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24477 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24479 | Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2448 | The reSmush.it WordPress plugin before 0.4.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when unfiltered_html is disallowed. | Unknown | N/A | Unknown | |
CVE-2022-24480 | Outlook for Android Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24481 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24482 | Windows ALPC Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24483 | Windows Kernel Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24484 | Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24485 | Win32 File Enumeration Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24486 | Windows Kerberos Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24487 | Windows Local Security Authority (LSA) Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24488 | Windows Desktop Bridge Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24489 | Cluster Client Failover (CCF) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2449 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 does not perform CSRF checks for any of its AJAX actions, allowing an attackers to trick logged in users to perform various actions on their behalf on the site. | Unknown | N/A | Unknown | |
CVE-2022-24490 | Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24491 | Windows Network File System Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24492 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24493 | Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24494 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24495 | Windows Direct Show - Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24496 | Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24497 | Windows Network File System Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24498 | Windows iSCSI Target Service Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24499 | Windows Installer Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2450 | The reSmush.it : the only free Image Optimizer & compress plugin WordPress plugin before 0.4.4 lacks authorization in various AJAX actions, allowing any logged-in users, such as subscribers to call them. | Unknown | N/A | Unknown | |
CVE-2022-24500 | Windows SMB Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24501 | VP9 Video Extensions Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24502 | Windows HTML Platforms Security Feature Bypass Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24503 | Remote Desktop Protocol Client Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24504 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24505 | Windows ALPC Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24506 | Azure Site Recovery Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24507 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24508 | Win32 File Enumeration Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24509 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24510 | Microsoft Office Visio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24511 | Microsoft Office Word Tampering Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24512 | .NET and Visual Studio Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24513 | Visual Studio Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24515 | Azure Site Recovery Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24516 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24517 | Azure Site Recovery Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24518 | Azure Site Recovery Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24519 | Azure Site Recovery Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24520 | Azure Site Recovery Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24521 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24522 | Skype Extension for Chrome Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24523 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24525 | Windows Update Stack Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24526 | Visual Studio Code Spoofing Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24527 | Microsoft Endpoint Configuration Manager Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24528 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2453 | Use After Free in GitHub repository gpac/gpac prior to 2.1-DEV. | Unknown | N/A | gpac | |
CVE-2022-24530 | Windows Installer Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24532 | HEVC Video Extensions Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24533 | Remote Desktop Protocol Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24534 | Win32 Stream Enumeration Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24536 | Windows DNS Server Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24537 | Windows Hyper-V Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24538 | Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24539 | Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2454 | Integer Overflow or Wraparound in GitHub repository gpac/gpac prior to 2.1-DEV. | Unknown | N/A | gpac | |
CVE-2022-24540 | Windows ALPC Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24541 | Windows Server Service Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24542 | Windows Win32k Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24543 | Windows Upgrade Assistant Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24544 | Windows Kerberos Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24545 | Windows Kerberos Remote Code Execution Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24546 | Windows DWM Core Library Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24547 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24548 | Microsoft Defender Denial of Service Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24549 | Windows AppX Package Manager Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-2455 | A business logic issue in the handling of large repositories in all versions of GitLab CE/EE from 10.0 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2 allowed an authenticated and authorized user to exhaust server resources by importing a malicious project. | Unknown | N/A | GitLab | |
CVE-2022-24550 | Windows Telephony Server Elevation of Privilege Vulnerability | Unknown | N/A | Microsoft | |
CVE-2022-24551 | A flaw was found in StarWind Stack. The endpoint for setting a new password doesn’t check the current username and old password. An attacker could reset any local user password (including system/administrator user) using any available user This affects StarWind SAN and NAS v0.2 build 1633. | Unknown | N/A | n/a | |
CVE-2022-24552 | A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject arbitrary data into the command that will be executed with root privileges. This affects StarWind SAN and NAS v0.2 build 1633. | Unknown | N/A | n/a | |
CVE-2022-24553 | An issue was found in Zfaka <= 1.4.5. The verification of the background file upload function check is not strict, resulting in remote command execution. | Unknown | N/A | n/a | |
CVE-2022-2456 | An issue has been discovered in GitLab CE/EE affecting all versions before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. It may be possible for malicious group or project maintainers to change their corresponding group or project visibility by crafting a malicious POST request. | Unknown | N/A | GitLab | |
CVE-2022-24562 | In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary read/write access to the entire file-system (with admin privileges) on the victim's endpoint, which can result in data theft and remote code execution. | Unknown | N/A | n/a | |
CVE-2022-24563 | In Genixcms v1.1.11, a stored Cross-Site Scripting (XSS) vulnerability exists in /gxadmin/index.php?page=themes&view=options" via the intro_title and intro_image parameters. | Unknown | N/A | n/a | |
CVE-2022-24564 | Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user. | Unknown | N/A | n/a | |
CVE-2022-24565 | Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications. | Unknown | N/A | n/a | |
CVE-2022-24566 | In Checkmk <=2.0.0p19 fixed in 2.0.0p20 and Checkmk <=1.6.0p27 fixed in 1.6.0p28, the title of a Predefined condition is not properly escaped when shown as condition, which can result in Cross Site Scripting (XSS). | Unknown | N/A | n/a | |
CVE-2022-24568 | Novel-plus v3.6.0 was discovered to be vulnerable to Server-Side Request Forgery (SSRF) via user-supplied crafted input. | Unknown | N/A | n/a | |
CVE-2022-2457 | A flaw was found in Red Hat Process Automation Manager 7 where an attacker can benefit from a brute force attack against Administration Console as the application does not limit the number of unsuccessful login attempts. | Unknown | N/A | n/a | |
CVE-2022-24571 | Car Driving School Management System v1.0 is affected by SQL injection in the login page. An attacker can use simple SQL login injection payload to get admin access. | Unknown | N/A | n/a | |
CVE-2022-24572 | Car Driving School Management System v1.0 is affected by Cross Site Scripting (XSS) in the User Enrollment Form (Username Field). To exploit this Vulnerability, an admin views the registered user details. | Unknown | N/A | n/a | |
CVE-2022-24573 | A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field. | Unknown | N/A | n/a | |
CVE-2022-24574 | GPAC 1.0.1 is affected by a NULL pointer dereference in gf_dump_vrml_field.isra (). | Unknown | N/A | n/a | |
CVE-2022-24575 | GPAC 1.0.1 is affected by a stack-based buffer overflow through MP4Box. | Unknown | N/A | n/a | |
CVE-2022-24576 | GPAC 1.0.1 is affected by Use After Free through MP4Box. | Unknown | N/A | n/a |
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v