The Wayback Machine - https://web.archive.org/web/20220215145652/https://nvd.nist.gov/
U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.



The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, misconfigurations, product names, and impact metrics.

Last 20 Scored Vulnerability IDs & Summaries CVSS Severity
  • CVE-2022-22716 - Microsoft Excel Information Disclosure Vulnerability.
    Published: February 09, 2022; 12:15:10 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 2.1 LOW

  • CVE-2022-22715 - Named Pipe File System Elevation of Privilege Vulnerability.
    Published: February 09, 2022; 12:15:10 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 7.2 HIGH

  • CVE-2022-22712 - Windows Hyper-V Denial of Service Vulnerability.
    Published: February 09, 2022; 12:15:10 PM -0500

    V3.1: 5.6 MEDIUM
    V2.0: 4.7 MEDIUM

  • CVE-2022-22710 - Windows Common Log File System Driver Denial of Service Vulnerability.
    Published: February 09, 2022; 12:15:10 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 4.9 MEDIUM

  • CVE-2022-21660 - Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as ... read CVE-2022-21660
    Published: February 09, 2022; 3:15:12 PM -0500

    V3.1: 8.1 HIGH
    V2.0: 5.5 MEDIUM

  • CVE-2021-45286 - Directory Traversal vulnerability exists in ZZCMS 2021 via the skin parameter in 1) index.php, 2) bottom.php, and 3) top_index.php.
    Published: February 09, 2022; 3:15:12 PM -0500

    V3.1: 5.3 MEDIUM
    V2.0: 5.0 MEDIUM

  • CVE-2022-22005 - Microsoft SharePoint Server Remote Code Execution Vulnerability.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 6.5 MEDIUM

  • CVE-2021-41442 - An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
    Published: February 09, 2022; 3:15:12 PM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2022-22003 - Microsoft Office Graphics Remote Code Execution Vulnerability.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2022-22002 - Windows User Account Profile Picture Denial of Service Vulnerability.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 5.5 MEDIUM
    V2.0: 4.9 MEDIUM

  • CVE-2022-22709 - VP9 Video Extensions Remote Code Execution Vulnerability.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2021-42833 - A Use of Hardcoded Credentials vulnerability exists in AquaView versions 1.60, 7.x, and 8.x that could allow an authenticated local attacker to manipulate users and system settings.
    Published: February 07, 2022; 2:15:08 PM -0500

    V3.1: 8.8 HIGH
    V2.0: 4.6 MEDIUM

  • CVE-2022-22004 - Microsoft Office ClickToRun Remote Code Execution Vulnerability.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 6.8 MEDIUM

  • CVE-2022-22001 - Windows Remote Access Connection Manager Elevation of Privilege Vulnerability.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 7.2 HIGH

  • CVE-2022-23320 - XMPie uStore 12.3.7244.0 allows for administrators to generate reports based on raw SQL queries. Since the application ships with default administrative credentials, an attacker may authenticate into the application and exfiltrate sensitive inform... read CVE-2022-23320
    Published: February 07, 2022; 6:15:07 AM -0500

    V3.1: 7.5 HIGH
    V2.0: 5.0 MEDIUM

  • CVE-2021-20877 - Cross-site scripting vulnerability in Canon laser printers and small office multifunctional printers (LBP162L/LBP162, MF4890dw, MF269dw/MF265dw/MF264dw/MF262dw, MF249dw/MF245dw/MF244dw/MF242dw/MF232w, and MF229dw/MF224dw/MF222dw sold in Japan, ima... read CVE-2021-20877
    Published: February 08, 2022; 6:15:07 AM -0500

    V3.1: 4.8 MEDIUM
    V2.0: 3.5 LOW

  • CVE-2022-22000 - Windows Common Log File System Driver Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-21981.
    Published: February 09, 2022; 12:15:09 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 7.2 HIGH

  • CVE-2021-41816 - CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem b... read CVE-2021-41816
    Published: February 06, 2022; 4:15:07 PM -0500

    V3.1: 9.8 CRITICAL
    V2.0: 7.5 HIGH

  • CVE-2022-0473 - OTRS administrators can configure dynamic field and inject malicious JavaScript code in the error message of the regular expression check. When used in the agent interface, malicious code might be exectued in the browser. This issue affects: OTRS ... read CVE-2022-0473
    Published: February 07, 2022; 6:15:07 AM -0500

    V3.1: 4.8 MEDIUM
    V2.0: 3.5 LOW

  • CVE-2022-20043 - In Bluetooth, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID... read CVE-2022-20043
    Published: February 09, 2022; 6:15:17 PM -0500

    V3.1: 7.8 HIGH
    V2.0: 4.6 MEDIUM