| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-29128 | Hig | 0.57 | 8.8 | 0.03 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-29126 | Hig | 0.46 | 7.0 | 0.01 | May 10, 2022 | Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | ||
| CVE-2022-29125 | Hig | 0.46 | 7.0 | 0.01 | May 10, 2022 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | ||
| CVE-2022-29117 | Hig | 0.49 | 7.5 | 0.05 | May 10, 2022 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2022-29115 | Hig | 0.51 | 7.8 | 0.02 | May 10, 2022 | Windows Fax Service Remote Code Execution Vulnerability | ||
| CVE-2022-29113 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | ||
| CVE-2022-29110 | Hig | 0.51 | 7.8 | 0.04 | May 10, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-29109 | Hig | 0.51 | 7.8 | 0.03 | May 10, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-29108 | Hig | 0.58 | 8.8 | 0.12 | May 10, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-29106 | Hig | 0.46 | 7.0 | 0.01 | May 10, 2022 | Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | ||
| CVE-2022-29105 | Hig | 0.51 | 7.8 | 0.03 | May 10, 2022 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | ||
| CVE-2022-29104 | Hig | 0.52 | 7.8 | 0.12 | May 10, 2022 | Windows Print Spooler Elevation of Privilege Vulnerability | ||
| CVE-2022-29103 | Hig | 0.51 | 7.8 | 0.01 | May 10, 2022 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | ||
| CVE-2022-26939 | Hig | 0.46 | 7.0 | 0.01 | May 10, 2022 | Storage Spaces Direct Elevation of Privilege Vulnerability | ||
| CVE-2022-26938 | Hig | 0.46 | 7.0 | 0.01 | May 10, 2022 | Storage Spaces Direct Elevation of Privilege Vulnerability | ||
| CVE-2022-26932 | Hig | 0.53 | 8.2 | 0.01 | May 10, 2022 | Storage Spaces Direct Elevation of Privilege Vulnerability | ||
| CVE-2022-26931 | Hig | 0.49 | 7.5 | 0.03 | May 10, 2022 | Windows Kerberos Elevation of Privilege Vulnerability | ||
| CVE-2022-26927 | Hig | 0.58 | 8.8 | 0.04 | May 10, 2022 | Windows Graphics Component Remote Code Execution Vulnerability | ||
| CVE-2022-26926 | Hig | 0.51 | 7.8 | 0.03 | May 10, 2022 | Windows Address Book Remote Code Execution Vulnerability | ||
| CVE-2022-26925 | Hig | 0.65 | 8.1 | 0.11 | KEV | May 10, 2022 | Windows LSA Spoofing Vulnerability | |
| CVE-2022-26923 | Hig | 0.79 | 8.8 | 0.83 | KEV | May 10, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability | |
| CVE-2022-26913 | Hig | 0.48 | 7.4 | 0.02 | May 10, 2022 | Windows Authentication Information Disclosure Vulnerability | ||
| CVE-2022-23279 | Hig | 0.46 | 7.0 | 0.05 | May 10, 2022 | Windows ALPC Elevation of Privilege Vulnerability | ||
| CVE-2022-23270 | Hig | 0.58 | 8.1 | 0.70 | May 10, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-23267 | Hig | 0.42 | 7.5 | 0.05 | May 10, 2022 | .NET and Visual Studio Denial of Service Vulnerability | ||
| CVE-2022-22019 | Hig | 0.57 | 8.8 | 0.03 | May 10, 2022 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | ||
| CVE-2022-22017 | Hig | 0.60 | 8.8 | 0.38 | May 10, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-22016 | Hig | 0.46 | 7.0 | 0.01 | May 10, 2022 | Windows PlayToManager Elevation of Privilege Vulnerability | ||
| CVE-2022-22014 | Hig | 0.57 | 8.8 | 0.02 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-22013 | Hig | 0.57 | 8.8 | 0.02 | May 10, 2022 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | ||
| CVE-2022-21978 | Hig | 0.53 | 8.2 | 0.01 | May 10, 2022 | Microsoft Exchange Server Elevation of Privilege Vulnerability | ||
| CVE-2022-21972 | Hig | 0.59 | 8.1 | 0.80 | May 10, 2022 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | ||
| CVE-2022-20118 | Hig | 0.46 | 7.0 | 0.00 | May 10, 2022 | In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:… | ||
| CVE-2021-39738 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-27167 | Hig | 0.46 | 7.1 | 0.00 | May 10, 2022 | Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET,… | ||
| CVE-2022-20116 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-20114 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User… | ||
| CVE-2022-20113 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not… | ||
| CVE-2022-20007 | Hig | 0.46 | 7.0 | 0.00 | May 10, 2022 | In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional… | ||
| CVE-2022-20006 | Hig | 0.46 | 7.0 | 0.00 | May 10, 2022 | In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no additional execution… | ||
| CVE-2022-20005 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… | ||
| CVE-2022-20004 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:… | ||
| CVE-2022-1463 | Hig | 0.57 | 8.8 | 0.02 | May 10, 2022 | The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site. | ||
| CVE-2022-1442 | Hig | 0.42 | 7.5 | 0.09 | May 10, 2022 | The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of… | ||
| CVE-2022-28986 | Hig | 0.49 | 7.5 | 0.02 | May 10, 2022 | LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts. | ||
| CVE-2022-23677 | Hig | 0.54 | 8.1 | 0.20 | May 10, 2022 | A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions;… | ||
| CVE-2021-46771 | Hig | 0.51 | 7.8 | 0.00 | May 10, 2022 | Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application. | ||
| CVE-2021-43010 | Hig | 0.49 | 7.5 | 0.01 | May 10, 2022 | In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data. | ||
| CVE-2021-26408 | Hig | 0.46 | 7.1 | 0.00 | May 10, 2022 | Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality. | ||
| CVE-2021-26370 | Hig | 0.46 | 7.1 | 0.00 | May 10, 2022 | Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability. |
- risk 0.57cvss 8.8epss 0.03
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Push Notifications Apps Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.05
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Fax Service Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.00
Windows Digital Media Receiver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.04
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.58cvss 8.8epss 0.12
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft Windows Media Foundation Remote Code Execution Vulnerability
- risk 0.52cvss 7.8epss 0.12
Windows Print Spooler Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Storage Spaces Direct Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Storage Spaces Direct Elevation of Privilege Vulnerability
- risk 0.53cvss 8.2epss 0.01
Storage Spaces Direct Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Kerberos Elevation of Privilege Vulnerability
- risk 0.58cvss 8.8epss 0.04
Windows Graphics Component Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Windows Address Book Remote Code Execution Vulnerability
- risk 0.65cvss 8.1epss 0.11
Windows LSA Spoofing Vulnerability
- risk 0.79cvss 8.8epss 0.83
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.48cvss 7.4epss 0.02
Windows Authentication Information Disclosure Vulnerability
- risk 0.46cvss 7.0epss 0.05
Windows ALPC Elevation of Privilege Vulnerability
- risk 0.58cvss 8.1epss 0.70
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.42cvss 7.5epss 0.05
.NET and Visual Studio Denial of Service Vulnerability
- risk 0.57cvss 8.8epss 0.03
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- risk 0.60cvss 8.8epss 0.38
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows PlayToManager Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.02
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- risk 0.53cvss 8.2epss 0.01
Microsoft Exchange Server Elevation of Privilege Vulnerability
- risk 0.59cvss 8.1epss 0.80
Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.00
In ion_ioctl and related functions of ion.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:…
- risk 0.51cvss 7.8epss 0.00
In CarSetings, there is a possible to pair BT device bypassing user's consent due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.46cvss 7.1epss 0.00
Privilege escalation vulnerability in Windows products of ESET, spol. s r.o. allows attacker to exploit "Repair" and "Uninstall" features what may lead to arbitrary file deletion. This issue affects: ESET, spol. s r.o. ESET NOD32 Antivirus 11.2 versions prior to 15.1.12.0. ESET,…
- risk 0.51cvss 7.8epss 0.00
In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.51cvss 7.8epss 0.00
In placeCall of TelecomManager.java, there is a possible way for an application to keep itself running with foreground service importance due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User…
- risk 0.51cvss 7.8epss 0.00
In mPreference of DefaultUsbConfigurationPreferenceController.java, there is a possible way to enable file transfer mode due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- risk 0.46cvss 7.0epss 0.00
In startActivityForAttachedApplicationIfNeeded of RootWindowContainer.java, there is a possible way to overlay an app that believes it's still in the foreground, when it is not, due to a race condition. This could lead to local escalation of privilege with no additional…
- risk 0.46cvss 7.0epss 0.00
In several functions of KeyguardServiceWrapper.java and related files,, there is a possible way to briefly view what's under the lockscreen due to a race condition. This could lead to local escalation of privilege if a Guest user is enabled, with no additional execution…
- risk 0.51cvss 7.8epss 0.00
In validateApkInstallLocked of PackageInstallerSession.java, there is a way to force a mismatch between running code and a parsed APK . This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…
- risk 0.51cvss 7.8epss 0.00
In checkSlicePermission of SliceManagerService.java, it is possible to access any slice URI due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product:…
- risk 0.57cvss 8.8epss 0.02
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.
- risk 0.42cvss 7.5epss 0.09
The Metform WordPress plugin is vulnerable to sensitive information disclosure due to improper access control in the ~/core/forms/action.php file which can be exploited by an unauthenticated attacker to view all API keys and secrets of integrated third-party APIs like that of…
- risk 0.49cvss 7.5epss 0.02
LMS Doctor Simple 2 Factor Authentication Plugin For Moodle Affected: 2021072900 has an Insecure direct object references (IDOR) vulnerability, which allows remote attackers to update sensitive records such as email, password and phone number of other user accounts.
- risk 0.54cvss 8.1epss 0.20
A remote execution of arbitrary code vulnerability was discovered in ArubaOS-Switch Devices version(s): ArubaOS-Switch 15.xx.xxxx: All versions; ArubaOS-Switch 16.01.xxxx: All versions; ArubaOS-Switch 16.02.xxxx: K.16.02.0033 and below; ArubaOS-Switch 16.03.xxxx: All versions;…
- risk 0.51cvss 7.8epss 0.00
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
- risk 0.49cvss 7.5epss 0.01
In Safedog Apache v4.0.30255, attackers can bypass this product for SQL injection. Attackers can bypass access to sensitive data.
- risk 0.46cvss 7.1epss 0.00
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
- risk 0.46cvss 7.1epss 0.00
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.