Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24518 1 Microsoft 1 Azure Site Recovery 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-22028 1 Microsoft 5 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 2 more 2023-08-08 4.3 MEDIUM 5.9 MEDIUM
Windows Network File System Information Disclosure Vulnerability
CVE-2022-24503 1 Microsoft 12 Remote Desktop, Windows 10, Windows 11 and 9 more 2023-08-08 5.0 MEDIUM 5.4 MEDIUM
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2021-39017 3 Ibm, Linux, Microsoft 3 Engineering Lifecycle Optimization Publishing, Linux Kernel, Windows 2023-08-08 N/A 6.5 MEDIUM
IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to upload arbitrary files, caused by improper access controls. IBM X-Force ID: 213725.
CVE-2022-2160 3 Fedoraproject, Google, Microsoft 3 Fedora, Chrome, Windows 2023-08-08 N/A 6.5 MEDIUM
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.
CVE-2022-24506 1 Microsoft 1 Azure Site Recovery 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-2622 3 Fedoraproject, Google, Microsoft 3 Fedora, Chrome, Windows 2023-08-08 N/A 6.5 MEDIUM
Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.
CVE-2022-1901 3 Linux, Microsoft, Octopus 3 Linux Kernel, Windows, Octopus Server 2023-08-08 N/A 5.3 MEDIUM
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
CVE-2022-24519 1 Microsoft 1 Azure Site Recovery 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35837 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2023-08-08 N/A 6.5 MEDIUM
Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-0803 4 Apple, Google, Linux and 1 more 4 Macos, Chrome, Linux Kernel and 1 more 2023-08-08 4.3 MEDIUM 6.5 MEDIUM
Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.
CVE-2022-24522 1 Microsoft 1 Skype Extension 2023-08-08 2.6 LOW 6.5 MEDIUM
Skype Extension for Chrome Information Disclosure Vulnerability
CVE-2022-22310 6 Apple, Hp, Ibm and 3 more 9 Macos, Hp-ux, Aix and 6 more 2023-08-08 6.4 MEDIUM 6.5 MEDIUM
IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 217224.
CVE-2021-42295 1 Microsoft 2 365 Apps, Office 2023-08-08 4.3 MEDIUM 5.5 MEDIUM
Visual Basic for Applications Information Disclosure Vulnerability
CVE-2022-21845 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 4.7 MEDIUM 4.7 MEDIUM
Windows Kernel Information Disclosure Vulnerability
CVE-2022-22716 1 Microsoft 7 365 Apps, Excel, Office and 4 more 2023-08-08 4.3 MEDIUM 5.5 MEDIUM
Microsoft Excel Information Disclosure Vulnerability
CVE-2022-22494 3 Ibm, Linux, Microsoft 4 Aix, Spectrum Protect Operations Center, Linux Kernel and 1 more 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
CVE-2022-0806 4 Apple, Google, Linux and 1 more 4 Macos, Chrome, Linux Kernel and 1 more 2023-08-08 4.3 MEDIUM 6.5 MEDIUM
Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page.
CVE-2022-33632 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-08-08 4.6 MEDIUM 4.7 MEDIUM
Microsoft Office Security Feature Bypass Vulnerability
CVE-2021-38879 3 Ibm, Linux, Microsoft 3 Jazz Team Server, Linux Kernel, Windows 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 209057.
CVE-2022-22373 3 Ibm, Linux, Microsoft 4 Aix, Infosphere Information Server, Linux Kernel and 1 more 2023-08-08 5.5 MEDIUM 5.4 MEDIUM
An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X-Force ID: 221323.
CVE-2022-22042 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Windows Hyper-V Information Disclosure Vulnerability
CVE-2021-38954 3 Ibm, Linux, Microsoft 4 Aix, Sterling B2b Integrator, Linux Kernel and 1 more 2023-08-08 4.0 MEDIUM 4.3 MEDIUM
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could disclose sensitive version information that could aid in future attacks against the system. IBM X-Force ID: 211414.
CVE-2022-22712 1 Microsoft 4 Windows 10, Windows 11, Windows Server and 1 more 2023-08-08 4.7 MEDIUM 5.6 MEDIUM
Windows Hyper-V Denial of Service Vulnerability
CVE-2022-22002 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2023-08-08 4.9 MEDIUM 5.5 MEDIUM
Windows User Account Profile Picture Denial of Service Vulnerability
CVE-2021-29701 3 Ibm, Linux, Microsoft 4 Engineering Workflow Management, Rational Team Concert, Linux Kernel and 1 more 2023-08-08 4.0 MEDIUM 4.3 MEDIUM
IBM Engineering Workflow Management 7.0, 7.0.1, and 7.0.2 as well as IBM Rational Team Concert 6.0.6 and 6.0.6.1 could allow an authneticated attacker to obtain sensitive information from build definitions that could aid in further attacks against the system. IBM X-Force ID: 200657.
CVE-2022-21968 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2023-08-08 4.0 MEDIUM 4.3 MEDIUM
Microsoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2022-1128 2 Google, Microsoft 2 Chrome, Windows 2023-08-08 N/A 6.5 MEDIUM
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page.
CVE-2021-42299 1 Microsoft 2 Surface Pro 3, Surface Pro 3 Firmware 2023-08-08 3.6 LOW 5.6 MEDIUM
Microsoft Surface Pro 3 Security Feature Bypass Vulnerability
CVE-2022-22711 1 Microsoft 6 Windows 10, Windows 11, Windows Server 2012 and 3 more 2023-08-08 3.3 LOW 5.7 MEDIUM
Windows BitLocker Information Disclosure Vulnerability
CVE-2022-22048 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 6.6 MEDIUM 6.1 MEDIUM
BitLocker Security Feature Bypass Vulnerability
CVE-2021-20355 3 Ibm, Linux, Microsoft 3 Jazz Team Server, Linux Kernel, Windows 2023-08-08 5.0 MEDIUM 5.3 MEDIUM
IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to set the HTTPOnly flag. A remote attacker could exploit this vulnerability to obtain sensitive information from the cookie. IBM X-Force ID: 194891.
CVE-2022-22319 2 Ibm, Microsoft 3 Robotic Process Automation, Robotic Process Automation As A Service, Windows 2023-08-08 5.5 MEDIUM 5.4 MEDIUM
IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366.
CVE-2022-22710 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 4.9 MEDIUM 5.5 MEDIUM
Windows Common Log File System Driver Denial of Service Vulnerability
CVE-2022-36772 3 Ibm, Linux, Microsoft 4 Aix, Infosphere Information Server, Linux Kernel and 1 more 2023-08-08 N/A 6.5 MEDIUM
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user.
CVE-2022-36774 2 Ibm, Microsoft 4 Robotic Process Automation, Robotic Process Automation As A Service, Robotic Process Automation For Cloud Pak and 1 more 2023-08-08 N/A 5.3 MEDIUM
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 is vulnerable to man in the middle attacks through manipulation of the client proxy configuration. IBM X-Force ID: 233575.
CVE-2022-23252 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2023-08-08 2.1 LOW 5.5 MEDIUM
Microsoft Office Information Disclosure Vulnerability
CVE-2022-21998 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 4.9 MEDIUM 5.5 MEDIUM
Windows Common Log File System Driver Information Disclosure Vulnerability
CVE-2022-38006 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2023-08-08 N/A 6.5 MEDIUM
Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-26816 1 Microsoft 3 Windows Server 2016, Windows Server 2019, Windows Server 2022 2023-08-08 4.0 MEDIUM 6.5 MEDIUM
Windows DNS Server Information Disclosure Vulnerability
CVE-2022-2188 2 Mcafee, Microsoft 2 Data Exchange Layer, Windows 2023-08-08 N/A 5.5 MEDIUM
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker.
CVE-2022-21985 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2023-08-08 2.1 LOW 5.5 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2022-41091 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2023-08-08 N/A 5.4 MEDIUM
Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2022-44699 1 Microsoft 1 Azure Network Watcher Agent 2023-08-08 N/A 5.5 MEDIUM
Azure Network Watcher Agent Security Feature Bypass Vulnerability
CVE-2022-41049 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2023-08-08 N/A 5.4 MEDIUM
Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2022-34362 3 Ibm, Linux, Microsoft 5 Aix, Linux On Ibm Z, Sterling Secure Proxy and 2 more 2023-08-08 N/A 4.6 MEDIUM
IBM Sterling Secure Proxy 6.0.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 230523.
CVE-2022-45432 2 Dahuasecurity, Microsoft 9 Dhi-dss4004-s2, Dhi-dss4004-s2 Firmware, Dhi-dss7016d-s2 and 6 more 2023-08-08 N/A 5.3 MEDIUM
Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices in range of IPs from remote DSS Server.
CVE-2022-45434 2 Dahuasecurity, Microsoft 9 Dhi-dss4004-s2, Dhi-dss4004-s2 Firmware, Dhi-dss7016d-s2 and 6 more 2023-08-08 N/A 5.9 MEDIUM
Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploit the victim server to launch ICMP request attack to the designated target host.
CVE-2022-30181 1 Microsoft 1 Azure Site Recovery 2023-08-08 5.5 MEDIUM 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2021-21126 2 Google, Microsoft 2 Chrome, Edge Chromium 2023-08-08 4.3 MEDIUM 6.5 MEDIUM
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a remote attacker to bypass site isolation via a crafted Chrome Extension.