CVE-2022-22715
Last Modified: 2 Jan 2025Named Pipe File System Elevation of Privilege Vulnerability
CVE-2022-22712
Last Modified: 2 Jan 2025Windows Hyper-V Denial of Service Vulnerability
CVE-2022-22710
Last Modified: 2 Jan 2025Windows Common Log File System Driver Denial of Service Vulnerability
CVE-2022-22709
Last Modified: 22 May 2026VP9 Video Extensions Remote Code Execution Vulnerability
CVE-2022-22005
Last Modified: 2 Jan 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-22004
Last Modified: 2 Jan 2025Microsoft Office ClickToRun Remote Code Execution Vulnerability
CVE-2022-22003
Last Modified: 2 Jan 2025Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2022-22002
Last Modified: 2 Jan 2025Windows User Account Profile Picture Denial of Service Vulnerability
CVE-2022-22001
Last Modified: 2 Jan 2025Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
CVE-2022-22000
Last Modified: 2 Jan 2025Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-21999
Last Modified: 30 Oct 2025Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21998
Last Modified: 2 Jan 2025Windows Common Log File System Driver Information Disclosure Vulnerability
CVE-2022-21997
Last Modified: 2 Jan 2025Windows Print Spooler Elevation of Privilege Vulnerability
CVE-2022-21996
Last Modified: 2 Jan 2025Win32k Elevation of Privilege Vulnerability
CVE-2022-21995
Last Modified: 2 Jan 2025Windows Hyper-V Remote Code Execution Vulnerability
CVE-2022-21994
Last Modified: 2 Jan 2025Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2022-21993
Last Modified: 2 Jan 2025Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability
CVE-2022-21992
Last Modified: 2 Jan 2025Windows Mobile Device Management Remote Code Execution Vulnerability
CVE-2022-21991
Last Modified: 2 Jan 2025Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
CVE-2022-21989
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-21988
Last Modified: 2 Jan 2025Microsoft Office Visio Remote Code Execution Vulnerability
CVE-2022-21987
Last Modified: 2 Jan 2025Microsoft SharePoint Server Spoofing Vulnerability
CVE-2022-21985
Last Modified: 2 Jan 2025Windows Remote Access Connection Manager Information Disclosure Vulnerability
CVE-2022-21984
Last Modified: 2 Jan 2025Windows DNS Server Remote Code Execution Vulnerability
CVE-2022-21981
Last Modified: 2 Jan 2025Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2022-21974
Last Modified: 2 Jan 2025Roaming Security Rights Management Services Remote Code Execution Vulnerability
CVE-2022-21971
Last Modified: 30 Oct 2025Windows Runtime Remote Code Execution Vulnerability
CVE-2022-21968
Last Modified: 2 Jan 2025Microsoft SharePoint Server Security Feature Bypass Vulnerability
CVE-2022-21965
Last Modified: 2 Jan 2025Microsoft Teams Denial of Service Vulnerability
CVE-2022-21957
Last Modified: 2 Jan 2025Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
CVE-2022-21927
Last Modified: 2 Jan 2025HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2022-21926
Last Modified: 2 Jan 2025HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2022-21844
Last Modified: 2 Jan 2025HEVC Video Extensions Remote Code Execution Vulnerability
CVE-2021-44912
Last Modified: 21 Nov 2024In XE 1.116, when uploading the Normal button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities. If the .htaccess configuration is improper, for example before the XE 1.11.2 version, you can upload the PHP type file to GETSHELL.
CVE-2021-44911
Last Modified: 21 Nov 2024XE before 1.11.6 is vulnerable to Unrestricted file upload via modules/menu/menu.admin.controller.php. When uploading the Mouse over button and When selected button, there is no restriction on the file suffix, which leads to any file uploading to the files directory. Since .htaccess only restricts the PHP type, uploading HTML-type files leads to stored XSS vulnerabilities.
CVE-2021-20002
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20004
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20003
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20005
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20006
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20007
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20008
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20009
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20010
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20011
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20012
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20013
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20014
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-20015
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
CVE-2021-37858
Last Modified: 7 Nov 2023DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2021. Notes: none
