Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 36333 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45180 1 Liveboxcloud 1 Vdesk 2026-06-17 N/A 6.5 MEDIUM
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdesk_{DOMAIN]/export endpoint. A malicious user, authenticated to the product without any specific privilege, can use the API for exporting information about all users of the system (an operation intended to only be available to the system administrator).
CVE-2022-45178 1 Liveboxcloud 1 Vdesk 2026-06-17 N/A 8.8 HIGH
An issue was discovered in LIVEBOX Collaboration vDesk through v018. Broken Access Control exists under the /api/v1/vdeskintegration/saml/user/createorupdate endpoint, the /settings/guest-settings endpoint, the /settings/samlusers-settings endpoint, and the /settings/users-settings endpoint. A malicious user (already logged in as a SAML User) is able to achieve privilege escalation from a low-privilege user (FGM user) to an administrative user (GGU user), including the administrator, or create new users even without an admin role.
CVE-2022-45112 1 Intel 1 Virtual Raid On Cpu 2026-06-17 N/A 7.3 HIGH
Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2022-45069 1 Automattic 1 Crowdsignal Dashboard 2026-06-17 N/A 6.3 MEDIUM
Auth. (contributor+) Privilege Escalation vulnerability in Crowdsignal Dashboard plugin <= 3.0.9 on WordPress.
CVE-2022-45060 4 Debian, Fedoraproject, Varnish-software and 1 more 5 Debian Linux, Fedora, Varnish Cache and 2 more 2026-06-17 N/A 7.5 HIGH
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
CVE-2022-45003 1 Getgophish 1 Gophish 2026-06-17 N/A 7.5 HIGH
Gophish through 0.12.1 allows attackers to cause a Denial of Service (DoS) via a crafted payload involving autofocus.
CVE-2022-44797 2 Btcd Project, Lightning Network Daemon Project 2 Btcd, Lightning Network Daemon 2026-06-17 N/A 9.8 CRITICAL
btcd before 0.23.2, as used in Lightning Labs lnd before 0.15.2-beta and other Bitcoin-related products, mishandles witness size checking.
CVE-2022-44794 1 Objectfirst 1 Ootbi 2026-06-17 N/A 8.8 HIGH
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary data goes directly to the Bash interpreter. An attacker would need credentials to exploit this vulnerability. This is fixed in Object First Ootbi BETA build 1.0.13.1611.
CVE-2022-44713 1 Microsoft 2 Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.5 HIGH
Microsoft Outlook for Mac Spoofing Vulnerability
CVE-2022-44710 1 Microsoft 1 Windows 11 2026-06-17 N/A 7.8 HIGH
DirectX Graphics Kernel Elevation of Privilege Vulnerability
CVE-2022-44708 1 Microsoft 2 Edge, Edge Chromium 2026-06-17 N/A 8.3 HIGH
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-44707 1 Microsoft 8 Windows 10, Windows 11, Windows 8.1 and 5 more 2026-06-17 N/A 6.5 MEDIUM
Windows Kernel Denial of Service Vulnerability
CVE-2022-44704 1 Microsoft 1 Windows Sysmon 2026-06-17 N/A 7.8 HIGH
Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability
CVE-2022-44702 1 Microsoft 3 Terminal, Windows 10, Windows 11 2026-06-17 N/A 7.8 HIGH
Windows Terminal Remote Code Execution Vulnerability
CVE-2022-44699 1 Microsoft 1 Azure Network Watcher Agent 2026-06-17 N/A 5.5 MEDIUM
Azure Network Watcher Agent Security Feature Bypass Vulnerability
CVE-2022-44698 1 Microsoft 10 Windows 10 1607, Windows 10 1809, Windows 10 20h2 and 7 more 2026-06-17 N/A 5.4 MEDIUM
Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2022-44697 1 Microsoft 10 Windows 10, Windows 11, Windows 7 and 7 more 2026-06-17 N/A 7.8 HIGH
Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2022-44696 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44695 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2026-06-17 N/A 7.8 HIGH
Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-44694 1 Microsoft 3 365 Apps, Office, Office Long Term Servicing Channel 2026-06-17 N/A 7.8 HIGH
Microsoft Office Visio Remote Code Execution Vulnerability