Vulnerabilities (CVE)

Filtered by vendor Microsoft
Angry Yack Logo
Total 22989 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36088 2 Microsoft, Thoughtworks 2 Windows, Gocd 2024-11-21 N/A 5.0 MEDIUM
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the server GoCD Server or Agent are installed on to modify executables or components of the installation. This does not affect zip file-based installs, installations to other platforms, or installations inside `Program Files` or ` ...

Show More

CVE-2022-36077 2 Electronjs, Microsoft 2 Electron, Windows 2024-11-21 N/A 7.2 HIGH
The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer following the redirect, but if the redirect target is a SMB URL such as `file://some.website.com/`, then i ...

Show More

CVE-2022-36070 2 Microsoft, Python-poetry 2 Windows, Poetry 2024-11-21 N/A 7.3 HIGH
Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute path. This can lead to the execution of untrusted code due to the way Windows resolves executable names to paths. Unlike Linux-based operating systems, Windows searches for the executable in the current directory first and looks in the paths that are defined in the ...

Show More

CVE-2022-35899 2 Asus, Microsoft 2 Aura Ready Game Software Development Kit, Windows 2024-11-21 N/A 7.8 HIGH
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.
CVE-2022-35841 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2024-11-21 N/A 8.8 HIGH
Windows Enterprise App Management Service Remote Code Execution Vulnerability
CVE-2022-35840 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2024-11-21 N/A 8.8 HIGH
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35838 1 Microsoft 2 Windows 11, Windows Server 2022 2024-11-21 N/A 7.5 HIGH
HTTP V3 Denial of Service Vulnerability
CVE-2022-35837 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2024-11-21 N/A 6.5 MEDIUM
Windows Graphics Component Information Disclosure Vulnerability
CVE-2022-35836 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2024-11-21 N/A 8.8 HIGH
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35835 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2024-11-21 N/A 8.8 HIGH
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35834 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2024-11-21 N/A 8.8 HIGH
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2022-35833 1 Microsoft 9 Windows 10, Windows 11, Windows 7 and 6 more 2024-11-21 N/A 7.5 HIGH
Windows Secure Channel Denial of Service Vulnerability
CVE-2022-35832 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2024-11-21 N/A 5.5 MEDIUM
Windows Event Tracing Denial of Service Vulnerability
CVE-2022-35831 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2024-11-21 N/A 5.5 MEDIUM
Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2022-35830 1 Microsoft 5 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 2 more 2024-11-21 N/A 8.1 HIGH
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2022-35827 1 Microsoft 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more 2024-11-21 N/A 8.8 HIGH
Visual Studio Remote Code Execution Vulnerability
CVE-2022-35826 1 Microsoft 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more 2024-11-21 N/A 8.8 HIGH
Visual Studio Remote Code Execution Vulnerability
CVE-2022-35825 1 Microsoft 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more 2024-11-21 N/A 8.8 HIGH
Visual Studio Remote Code Execution Vulnerability
CVE-2022-35824 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 7.2 HIGH
Azure Site Recovery Remote Code Execution Vulnerability
CVE-2022-35823 1 Microsoft 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server 2024-11-21 N/A 8.8 HIGH
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2022-35822 1 Microsoft 5 Windows 10, Windows 11, Windows Server 2016 and 2 more 2024-11-21 N/A 7.1 HIGH
Windows Defender Credential Guard Security Feature Bypass Vulnerability
CVE-2022-35821 1 Microsoft 1 Azure Sphere 2024-11-21 N/A 4.4 MEDIUM
Azure Sphere Information Disclosure Vulnerability
CVE-2022-35820 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2024-11-21 N/A 7.8 HIGH
Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2022-35819 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35818 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35817 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35816 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35815 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35814 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35813 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35812 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 4.9 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35811 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35810 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35809 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35808 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35807 1 Microsoft 1 Azure Site Recovery 2024-11-21 N/A 6.5 MEDIUM
Azure Site Recovery Elevation of Privilege Vulnerability
CVE-2022-35806 1 Microsoft 1 Azure Real Time Operating System Guix Studio 2024-11-21 N/A 7.8 HIGH
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
CVE-2022-35805 1 Microsoft 1 Dynamics 365 2024-11-21 N/A 8.8 HIGH
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
CVE-2022-35804 1 Microsoft 1 Windows 11 2024-11-21 N/A 8.8 HIGH
SMB Client and Server Remote Code Execution Vulnerability
CVE-2022-35803 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2024-11-21 N/A 7.8 HIGH
Windows Common Log File System Driver Elevation of Privilege Vulnerability