Filtered by vendor Microsoft
Subscribe
Total
22989 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2022-36088 | 2 Microsoft, Thoughtworks | 2 Windows, Gocd | 2024-11-21 | N/A | 5.0 MEDIUM |
|
GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local access to the server GoCD Server or Agent are installed on to modify executables or components of the installation. This does not affect zip file-based installs, installations to other platforms, or installations inside `Program Files` or ` ...
Show More |
|||||
| CVE-2022-36077 | 2 Electronjs, Microsoft | 2 Electron, Windows | 2024-11-21 | N/A | 7.2 HIGH |
|
The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer following the redirect, but if the redirect target is a SMB URL such as `file://some.website.com/`, then i ...
Show More |
|||||
| CVE-2022-36070 | 2 Microsoft, Python-poetry | 2 Windows, Poetry | 2024-11-21 | N/A | 7.3 HIGH |
|
Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute path. This can lead to the execution of untrusted code due to the way Windows resolves executable names to paths. Unlike Linux-based operating systems, Windows searches for the executable in the current directory first and looks in the paths that are defined in the ...
Show More |
|||||
| CVE-2022-35899 | 2 Asus, Microsoft | 2 Aura Ready Game Software Development Kit, Windows | 2024-11-21 | N/A | 7.8 HIGH |
|
There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file.
|
|||||
| CVE-2022-35841 | 1 Microsoft | 5 Windows 10, Windows 11, Windows Server 2016 and 2 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Windows Enterprise App Management Service Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35840 | 1 Microsoft | 9 Windows 10, Windows 11, Windows 7 and 6 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35838 | 1 Microsoft | 2 Windows 11, Windows Server 2022 | 2024-11-21 | N/A | 7.5 HIGH |
|
HTTP V3 Denial of Service Vulnerability
|
|||||
| CVE-2022-35837 | 1 Microsoft | 9 Windows 10, Windows 11, Windows 7 and 6 more | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Windows Graphics Component Information Disclosure Vulnerability
|
|||||
| CVE-2022-35836 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35835 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35834 | 1 Microsoft | 9 Windows 10, Windows 11, Windows 7 and 6 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35833 | 1 Microsoft | 9 Windows 10, Windows 11, Windows 7 and 6 more | 2024-11-21 | N/A | 7.5 HIGH |
|
Windows Secure Channel Denial of Service Vulnerability
|
|||||
| CVE-2022-35832 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | N/A | 5.5 MEDIUM |
|
Windows Event Tracing Denial of Service Vulnerability
|
|||||
| CVE-2022-35831 | 1 Microsoft | 8 Windows 10, Windows 11, Windows 8.1 and 5 more | 2024-11-21 | N/A | 5.5 MEDIUM |
|
Windows Remote Access Connection Manager Information Disclosure Vulnerability
|
|||||
| CVE-2022-35830 | 1 Microsoft | 5 Windows Server 2008, Windows Server 2012, Windows Server 2016 and 2 more | 2024-11-21 | N/A | 8.1 HIGH |
|
Remote Procedure Call Runtime Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35827 | 1 Microsoft | 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Visual Studio Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35826 | 1 Microsoft | 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Visual Studio Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35825 | 1 Microsoft | 4 Visual Studio, Visual Studio 2017, Visual Studio 2019 and 1 more | 2024-11-21 | N/A | 8.8 HIGH |
|
Visual Studio Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35824 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 7.2 HIGH |
|
Azure Site Recovery Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35823 | 1 Microsoft | 3 Sharepoint Enterprise Server, Sharepoint Foundation, Sharepoint Server | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft SharePoint Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35822 | 1 Microsoft | 5 Windows 10, Windows 11, Windows Server 2016 and 2 more | 2024-11-21 | N/A | 7.1 HIGH |
|
Windows Defender Credential Guard Security Feature Bypass Vulnerability
|
|||||
| CVE-2022-35821 | 1 Microsoft | 1 Azure Sphere | 2024-11-21 | N/A | 4.4 MEDIUM |
|
Azure Sphere Information Disclosure Vulnerability
|
|||||
| CVE-2022-35820 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Bluetooth Driver Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35819 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35818 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35817 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35816 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35815 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35814 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35813 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35812 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 4.9 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35811 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35810 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35809 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35808 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35807 | 1 Microsoft | 1 Azure Site Recovery | 2024-11-21 | N/A | 6.5 MEDIUM |
|
Azure Site Recovery Elevation of Privilege Vulnerability
|
|||||
| CVE-2022-35806 | 1 Microsoft | 1 Azure Real Time Operating System Guix Studio | 2024-11-21 | N/A | 7.8 HIGH |
|
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35805 | 1 Microsoft | 1 Dynamics 365 | 2024-11-21 | N/A | 8.8 HIGH |
|
Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35804 | 1 Microsoft | 1 Windows 11 | 2024-11-21 | N/A | 8.8 HIGH |
|
SMB Client and Server Remote Code Execution Vulnerability
|
|||||
| CVE-2022-35803 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2024-11-21 | N/A | 7.8 HIGH |
|
Windows Common Log File System Driver Elevation of Privilege Vulnerability
|
|||||