Vulnerabilities (CVE)

Filtered by NVD-CWE-noinfo
Total 36333 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-29405 1 Apache 1 Archiva 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8
CVE-2022-29264 1 Coreboot 1 Coreboot 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue was discovered in coreboot 4.13 through 4.16. On APs, arbitrary code execution in SMM may occur.
CVE-2022-29262 1 Intel 66 Compute Module Hns2600bpb, Compute Module Hns2600bpb24, Compute Module Hns2600bpb24 Firmware and 63 more 2026-06-17 N/A 7.9 HIGH
Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2022-29257 1 Electronjs 1 Electron 2026-06-17 6.5 MEDIUM 6.6 MEDIUM
Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.
CVE-2022-29244 2 Netapp, Npmjs 2 Ontap Select Deploy Administration Utility, Npm 2026-06-17 5.0 MEDIUM 7.5 HIGH
npm pack ignores root-level .gitignore and .npmignore file exclusion directives when run in a workspace or with a workspace flag (ie. `--workspaces`, `--workspace=<name>`). Anyone who has run `npm pack` or `npm publish` inside a workspace, as of v7.9.0 and v7.13.0 respectively, may be affected and have published files into the npm registry they did not intend to include. Users should upgrade to the latest, patched version of npm v8.11.0, run: npm i -g npm@latest . Node.js versions v16.15.1, v17.19.1, and v18.3.0 include the patched v8.11.0 version of npm.
CVE-2022-29241 1 Jupyter 1 Jupyter Server 2026-06-17 9.0 HIGH 7.1 HIGH
Jupyter Server provides the backend (i.e. the core services, APIs, and REST endpoints) for Jupyter web applications like Jupyter Notebook. Prior to version 1.17.1, if notebook server is started with a value of `root_dir` that contains the starting user's home directory, then the underlying REST API can be used to leak the access token assigned at start time by guessing/brute forcing the PID of the jupyter server. While this requires an authenticated user session, this URL can be used from a cross-site scripting payload or from a hooked or otherwise compromised browser to leak this access token to a malicious third party. This token can be used along with the REST API to interact with Jupyter services/notebooks such as modifying or overwriting critical files, such as .bashrc or .ssh/authorized_keys, allowing a malicious user to read potentially sensitive data and possibly gain control of the impacted system. This issue is patched in version 1.17.1.
CVE-2022-29177 1 Ethereum 1 Go Ethereum 2026-06-17 4.3 MEDIUM 5.9 MEDIUM
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.17, a vulnerable node, if configured to use high verbosity logging, can be made to crash when handling specially crafted p2p messages sent from an attacker node. Version 1.10.17 contains a patch that addresses the problem. As a workaround, setting loglevel to default level (`INFO`) makes the node not vulnerable to this attack.
CVE-2022-29164 1 Argoproj 1 Argo Workflows 2026-06-17 4.6 MEDIUM 7.1 HIGH
Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. In affected versions an attacker can create a workflow which produces a HTML artifact containing an HTML file that contains a script which uses XHR calls to interact with the Argo Server API. The attacker emails the deep-link to the artifact to their victim. The victim opens the link, the script starts running. As the script has access to the Argo Server API (as the victim), so may read information about the victim’s workflows, or create and delete workflows. Note the attacker must be an insider: they must have access to the same cluster as the victim and must already be able to run their own workflows. The attacker must have an understanding of the victim’s system. We have seen no evidence of this in the wild. We urge all users to upgrade to the fixed versions.
CVE-2022-29151 1 Microsoft 5 Windows Server, Windows Server 2012, Windows Server 2016 and 2 more 2026-06-17 6.9 MEDIUM 7.0 HIGH
Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
CVE-2022-29150 1 Microsoft 5 Windows Server, Windows Server 2012, Windows Server 2016 and 2 more 2026-06-17 6.9 MEDIUM 7.0 HIGH
Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability
CVE-2022-29149 1 Microsoft 10 Azure Automation State Configuration, Azure Automation Update Management, Azure Diagnostics and 7 more 2026-06-17 4.6 MEDIUM 7.8 HIGH
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
CVE-2022-29148 1 Microsoft 1 Visual Studio 2017 2026-06-17 6.8 MEDIUM 7.8 HIGH
Visual Studio Remote Code Execution Vulnerability
CVE-2022-29147 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 3.1 LOW
Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2022-29146 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 8.3 HIGH
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-29145 2 Fedoraproject, Microsoft 5 Fedora, .net, .net Core and 2 more 2026-06-17 5.0 MEDIUM 7.5 HIGH
.NET and Visual Studio Denial of Service Vulnerability
CVE-2022-29144 1 Microsoft 1 Edge Chromium 2026-06-17 N/A 7.5 HIGH
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2022-29143 1 Microsoft 1 Sql Server 2026-06-17 6.0 MEDIUM 7.5 HIGH
Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2022-29142 1 Microsoft 4 Windows 10, Windows Server, Windows Server 2019 and 1 more 2026-06-17 6.9 MEDIUM 7.0 HIGH
Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-29141 1 Microsoft 11 Windows 10, Windows 11, Windows 7 and 8 more 2026-06-17 6.5 MEDIUM 8.8 HIGH
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-29140 1 Microsoft 6 Windows 10, Windows 11, Windows Server and 3 more 2026-06-17 2.1 LOW 5.5 MEDIUM
Windows Print Spooler Information Disclosure Vulnerability