| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-21887 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Win32k Elevation of Privilege Vulnerability | ||
| CVE-2022-21885 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | ||
| CVE-2022-21884 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | ||
| CVE-2022-21883 | Hig | 0.49 | 7.5 | 0.04 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2022-21882 | Hig | 0.65 | 7.0 | 0.56 | KEV | Jan 11, 2022 | Win32k Elevation of Privilege Vulnerability | |
| CVE-2022-21881 | Hig | 0.48 | 7.0 | 0.25 | Jan 11, 2022 | Windows Kernel Elevation of Privilege Vulnerability | ||
| CVE-2022-21880 | Hig | 0.49 | 7.5 | 0.04 | Jan 11, 2022 | Windows GDI+ Information Disclosure Vulnerability | ||
| CVE-2022-21878 | Hig | 0.51 | 7.8 | 0.03 | Jan 11, 2022 | Windows Geolocation Service Remote Code Execution Vulnerability | ||
| CVE-2022-21875 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows Storage Elevation of Privilege Vulnerability | ||
| CVE-2022-21874 | Hig | 0.51 | 7.8 | 0.02 | Jan 11, 2022 | Windows Security Center API Remote Code Execution Vulnerability | ||
| CVE-2022-21873 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Tile Data Repository Elevation of Privilege Vulnerability | ||
| CVE-2022-21872 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows Event Tracing Elevation of Privilege Vulnerability | ||
| CVE-2022-21871 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability | ||
| CVE-2022-21870 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | ||
| CVE-2022-21869 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Clipboard User Service Elevation of Privilege Vulnerability | ||
| CVE-2022-21868 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows Devices Human Interface Elevation of Privilege Vulnerability | ||
| CVE-2022-21867 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | ||
| CVE-2022-21866 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows System Launcher Elevation of Privilege Vulnerability | ||
| CVE-2022-21865 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Connected Devices Platform Service Elevation of Privilege Vulnerability | ||
| CVE-2022-21864 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows UI Immersive Server API Elevation of Privilege Vulnerability | ||
| CVE-2022-21863 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows StateRepository API Server file Elevation of Privilege Vulnerability | ||
| CVE-2022-21862 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows Application Model Core API Elevation of Privilege Vulnerability | ||
| CVE-2022-21861 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Task Flow Data Engine Elevation of Privilege Vulnerability | ||
| CVE-2022-21860 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows AppContracts API Server Elevation of Privilege Vulnerability | ||
| CVE-2022-21859 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows Accounts Control Elevation of Privilege Vulnerability | ||
| CVE-2022-21858 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Bind Filter Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-21857 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Active Directory Domain Services Elevation of Privilege Vulnerability | ||
| CVE-2022-21852 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows DWM Core Library Elevation of Privilege Vulnerability | ||
| CVE-2022-21851 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-21850 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2022-21848 | Hig | 0.49 | 7.5 | 0.04 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | ||
| CVE-2022-21843 | Hig | 0.49 | 7.5 | 0.03 | Jan 11, 2022 | Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | ||
| CVE-2022-21842 | Hig | 0.51 | 7.8 | 0.02 | Jan 11, 2022 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2022-21841 | Hig | 0.51 | 7.8 | 0.03 | Jan 11, 2022 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2022-21840 | Hig | 0.57 | 8.8 | 0.03 | Jan 11, 2022 | Microsoft Office Remote Code Execution Vulnerability | ||
| CVE-2022-21837 | Hig | 0.54 | 8.3 | 0.03 | Jan 11, 2022 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2022-21836 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Windows Certificate Spoofing Vulnerability | ||
| CVE-2022-21835 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Microsoft Cryptographic Services Elevation of Privilege Vulnerability | ||
| CVE-2022-21834 | Hig | 0.46 | 7.0 | 0.01 | Jan 11, 2022 | Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability | ||
| CVE-2022-21833 | Hig | 0.51 | 7.8 | 0.01 | Jan 11, 2022 | Virtual Machine IDE Drive Elevation of Privilege Vulnerability | ||
| CVE-2021-43973 | Hig | 0.57 | 8.8 | 0.02 | Jan 11, 2022 | An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of… | ||
| CVE-2021-43971 | Hig | 0.57 | 8.8 | 0.02 | Jan 11, 2022 | A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter. | ||
| CVE-2021-43054 | Hig | 0.46 | 7.1 | 0.01 | Jan 11, 2022 | The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows a low privileged attacker with network access to generate API tokens… | ||
| CVE-2021-43053 | Hig | 0.55 | 8.5 | 0.01 | Jan 11, 2022 | The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a difficult to exploit vulnerability that allows an unauthenticated attacker with network access to obtain the cluster… | ||
| CVE-2021-34704 | Hig | 0.56 | 8.6 | 0.01 | Jan 11, 2022 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to… | ||
| CVE-2021-1573 | Hig | 0.56 | 8.6 | 0.01 | Jan 11, 2022 | A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to… | ||
| CVE-2022-0129 | Hig | 0.48 | 7.4 | 0.00 | Jan 11, 2022 | Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory… | ||
| CVE-2021-38991 | Hig | 0.51 | 7.8 | 0.00 | Jan 11, 2022 | IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953. | ||
| CVE-2022-21671 | Hig | 0.46 | 8.1 | 0.01 | Jan 11, 2022 | @replit/crosis is a JavaScript client that speaks Replit's container protocol. A vulnerability that involves exposure of sensitive information exists in versions prior to 7.3.1. When using this library as a way to programmatically communicate with Replit in a standalone fashion,… | ||
| CVE-2021-45460 | Hig | 0.53 | 8.1 | 0.01 | Jan 11, 2022 | A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of… |
- risk 0.46cvss 7.0epss 0.01
Win32k Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Local Security Authority Subsystem Service Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.65cvss 7.0epss 0.56
Win32k Elevation of Privilege Vulnerability
- risk 0.48cvss 7.0epss 0.25
Windows Kernel Elevation of Privilege Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows GDI+ Information Disclosure Vulnerability
- risk 0.51cvss 7.8epss 0.03
Windows Geolocation Service Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Storage Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.02
Windows Security Center API Remote Code Execution Vulnerability
- risk 0.46cvss 7.0epss 0.01
Tile Data Repository Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Event Tracing Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Clipboard User Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Devices Human Interface Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Push Notifications Apps Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows System Launcher Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Connected Devices Platform Service Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows UI Immersive Server API Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows StateRepository API Server file Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Application Model Core API Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Task Flow Data Engine Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows AppContracts API Server Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows Accounts Control Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Bind Filter Driver Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Active Directory Domain Services Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows DWM Core Library Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.03
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.04
Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
- risk 0.49cvss 7.5epss 0.03
Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.02
Microsoft Word Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.03
Microsoft Office Remote Code Execution Vulnerability
- risk 0.54cvss 8.3epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Windows Certificate Spoofing Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Cryptographic Services Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Virtual Machine IDE Drive Elevation of Privilege Vulnerability
- risk 0.57cvss 8.8epss 0.02
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of…
- risk 0.57cvss 8.8epss 0.02
A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
- risk 0.46cvss 7.1epss 0.01
The eFTL Server component of TIBCO Software Inc.'s TIBCO eFTL - Community Edition, TIBCO eFTL - Developer Edition, and TIBCO eFTL - Enterprise Edition contains an easily exploitable vulnerability that allows a low privileged attacker with network access to generate API tokens…
- risk 0.55cvss 8.5epss 0.01
The Realm Server component of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a difficult to exploit vulnerability that allows an unauthenticated attacker with network access to obtain the cluster…
- risk 0.56cvss 8.6epss 0.01
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to…
- risk 0.56cvss 8.6epss 0.01
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to…
- risk 0.48cvss 7.4epss 0.00
Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory…
- risk 0.51cvss 7.8epss 0.00
IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.
- risk 0.46cvss 8.1epss 0.01
@replit/crosis is a JavaScript client that speaks Replit's container protocol. A vulnerability that involves exposure of sensitive information exists in versions prior to 7.3.1. When using this library as a way to programmatically communicate with Replit in a standalone fashion,…
- risk 0.53cvss 8.1epss 0.01
A vulnerability has been identified in SICAM PQ Analyzer (All versions < V3.18). A service is started by an unquoted registry entry. As there are spaces in this path, attackers with write privilege to those directories might be able to plant executables that will run in place of…