‼ CVE-2022-1463 ‼
📖 Read
via "National Vulnerability Database".
The Booking Calendar plugin for WordPress is vulnerable to PHP Object Injection via the [bookingflextimeline] shortcode in versions up to, and including, 9.1. This could be exploited by subscriber-level users and above to call arbitrary PHP objects on a vulnerable site.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-1505 ‼
📖 Read
via "National Vulnerability Database".
The RSVPMaker plugin for WordPress is vulnerable to unauthenticated SQL Injection due to missing SQL escaping and parameterization on user supplied data passed to a SQL query in the rsvpmaker-api-endpoints.php file. This makes it possible for unauthenticated attackers to steal sensitive information from the database in versions up to and including 9.2.6.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29397 ‼
📖 Read
via "National Vulnerability Database".
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the comment parameter in the function FUN_004196c8.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29132 ‼
📖 Read
via "National Vulnerability Database".
Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29104.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29137 ‼
📖 Read
via "National Vulnerability Database".
Windows LDAP Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-22012, CVE-2022-22013, CVE-2022-22014, CVE-2022-29128, CVE-2022-29129, CVE-2022-29130, CVE-2022-29131, CVE-2022-29139, CVE-2022-29141.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29125 ‼
📖 Read
via "National Vulnerability Database".
Windows Push Notifications Apps Elevation of Privilege Vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-22011 ‼
📖 Read
via "National Vulnerability Database".
Windows Graphics Component Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-26934, CVE-2022-29112.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29140 ‼
📖 Read
via "National Vulnerability Database".
Windows Print Spooler Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-29114.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-20117 ‼
📖 Read
via "National Vulnerability Database".
In (TBD) of (TBD), there is a possible way to decrypt local data encrypted by the GSC due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-217475903References: N/A📖 Read
via "National Vulnerability Database".
‼ CVE-2022-22016 ‼
📖 Read
via "National Vulnerability Database".
Windows PlayToManager Elevation of Privilege Vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-26936 ‼
📖 Read
via "National Vulnerability Database".
Windows Server Service Information Disclosure Vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29102 ‼
📖 Read
via "National Vulnerability Database".
Windows Failover Cluster Information Disclosure Vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-21978 ‼
📖 Read
via "National Vulnerability Database".
Microsoft Exchange Server Elevation of Privilege Vulnerability.📖 Read
via "National Vulnerability Database".
🤔1
‼ CVE-2022-29112 ‼
📖 Read
via "National Vulnerability Database".
Windows Graphics Component Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-22011, CVE-2022-26934.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29133 ‼
📖 Read
via "National Vulnerability Database".
Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29142.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-20116 ‼
📖 Read
via "National Vulnerability Database".
In onEntryUpdated of OngoingCallController.kt, it is possible to launch non-exported activities due to intent redirection. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12LAndroid ID: A-212467440📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29135 ‼
📖 Read
via "National Vulnerability Database".
Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-29150, CVE-2022-29151.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29398 ‼
📖 Read
via "National Vulnerability Database".
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the File parameter in the function FUN_0041309c.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29109 ‼
📖 Read
via "National Vulnerability Database".
Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-29110.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-29148 ‼
📖 Read
via "National Vulnerability Database".
Visual Studio Remote Code Execution Vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-30129 ‼
📖 Read
via "National Vulnerability Database".
Visual Studio Code Remote Code Execution Vulnerability.📖 Read
via "National Vulnerability Database".