Show filters
40,693 Total Results
Displaying 241-250 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2022-41128

Disclosure Date: November 09, 2022 (last updated January 11, 2025)
Windows Scripting Languages Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2022-3723

Disclosure Date: November 01, 2022 (last updated June 29, 2024)
Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2022-3201

Disclosure Date: September 26, 2022 (last updated November 25, 2023)
Insufficient validation of untrusted input in DevTools in Google Chrome on Chrome OS prior to 105.0.5195.125 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2022-2856

Disclosure Date: September 26, 2022 (last updated June 29, 2024)
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page.
Attacker Value
Unknown

CVE-2022-40143

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2021-44076

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
An issue was discovered in CrushFTP 9. The creation of a new user through the /WebInterface/UserManager/ interface allows an attacker, with access to the administration panel, to perform Stored Cross-Site Scripting (XSS). The payload can be executed in multiple scenarios, for example when the user's page appears in the Most Visited section of the page.
Attacker Value
Unknown

CVE-2022-32893

Disclosure Date: August 24, 2022 (last updated November 08, 2023)
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1, Safari 15.6.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Attacker Value
Unknown

CVE-2022-34713

Disclosure Date: August 09, 2022 (last updated January 11, 2025)
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2022-22959

Disclosure Date: April 13, 2022 (last updated October 07, 2023)
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a cross site request forgery vulnerability. A malicious actor can trick a user through a cross site request forgery to unintentionally validate a malicious JDBC URI.
Attacker Value
Unknown

CVE-2021-23180

Disclosure Date: March 02, 2022 (last updated October 07, 2023)
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.