CVE-2022-21881
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-21880
Last Modified: 2 Jan 2025Windows GDI+ Information Disclosure Vulnerability
CVE-2022-21879
Last Modified: 2 Jan 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2022-21878
Last Modified: 2 Jan 2025Windows Geolocation Service Remote Code Execution Vulnerability
CVE-2022-21877
Last Modified: 2 Jan 2025Storage Spaces Controller Information Disclosure Vulnerability
CVE-2022-21876
Last Modified: 2 Jan 2025Win32k Information Disclosure Vulnerability
CVE-2022-21875
Last Modified: 2 Jan 2025Windows Storage Elevation of Privilege Vulnerability
CVE-2022-21873
Last Modified: 2 Jan 2025Tile Data Repository Elevation of Privilege Vulnerability
CVE-2022-21874
Last Modified: 2 Jan 2025Windows Security Center API Remote Code Execution Vulnerability
CVE-2022-21872
Last Modified: 2 Jan 2025Windows Event Tracing Elevation of Privilege Vulnerability
CVE-2022-21871
Last Modified: 2 Jan 2025Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability
CVE-2022-21869
Last Modified: 2 Jan 2025Clipboard User Service Elevation of Privilege Vulnerability
CVE-2022-21870
Last Modified: 2 Jan 2025Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability
CVE-2022-21868
Last Modified: 2 Jan 2025Windows Devices Human Interface Elevation of Privilege Vulnerability
CVE-2022-21867
Last Modified: 2 Jan 2025Windows Push Notifications Apps Elevation of Privilege Vulnerability
CVE-2022-21866
Last Modified: 2 Jan 2025Windows System Launcher Elevation of Privilege Vulnerability
CVE-2022-21865
Last Modified: 2 Jan 2025Connected Devices Platform Service Elevation of Privilege Vulnerability
CVE-2022-21863
Last Modified: 2 Jan 2025Windows StateRepository API Server file Elevation of Privilege Vulnerability
CVE-2022-21864
Last Modified: 2 Jan 2025Windows UI Immersive Server API Elevation of Privilege Vulnerability
CVE-2022-21862
Last Modified: 2 Jan 2025Windows Application Model Core API Elevation of Privilege Vulnerability
CVE-2022-21861
Last Modified: 2 Jan 2025Task Flow Data Engine Elevation of Privilege Vulnerability
CVE-2022-21860
Last Modified: 2 Jan 2025Windows AppContracts API Server Elevation of Privilege Vulnerability
CVE-2022-21859
Last Modified: 2 Jan 2025Windows Accounts Control Elevation of Privilege Vulnerability
CVE-2022-21857
Last Modified: 2 Jan 2025Active Directory Domain Services Elevation of Privilege Vulnerability
CVE-2022-21858
Last Modified: 2 Jan 2025Windows Bind Filter Driver Elevation of Privilege Vulnerability
CVE-2022-21855
Last Modified: 2 Jan 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-21852
Last Modified: 2 Jan 2025Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2022-21851
Last Modified: 2 Jan 2025Remote Desktop Client Remote Code Execution Vulnerability
CVE-2022-21849
Last Modified: 2 Jan 2025Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
CVE-2022-21850
Last Modified: 2 Jan 2025Remote Desktop Client Remote Code Execution Vulnerability
CVE-2022-21848
Last Modified: 2 Jan 2025Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability
CVE-2022-21847
Last Modified: 2 Jan 2025Windows Hyper-V Denial of Service Vulnerability
CVE-2022-21846
Last Modified: 2 Jan 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2022-21842
Last Modified: 2 Jan 2025Microsoft Word Remote Code Execution Vulnerability
CVE-2022-21843
Last Modified: 2 Jan 2025Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability
CVE-2022-21841
Last Modified: 19 May 2026Microsoft Excel Remote Code Execution Vulnerability
CVE-2022-21840
Last Modified: 19 May 2026Microsoft Office Remote Code Execution Vulnerability
CVE-2022-21839
Last Modified: 2 Jan 2025Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability
CVE-2022-21838
Last Modified: 2 Jan 2025Windows Cleanup Manager Elevation of Privilege Vulnerability
CVE-2022-21837
Last Modified: 2 Jan 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2022-21836
Last Modified: 2 Jan 2025Windows Certificate Spoofing Vulnerability
CVE-2022-21835
Last Modified: 2 Jan 2025Microsoft Cryptographic Services Elevation of Privilege Vulnerability
CVE-2022-21834
Last Modified: 2 Jan 2025Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability
CVE-2022-21833
Last Modified: 2 Jan 2025Virtual Machine IDE Drive Elevation of Privilege Vulnerability
CVE-2021-43974
Last Modified: 21 Nov 2024An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register end users anonymously, but does not respect the server-side setting that determines if anonymous users are allowed to register new accounts. Configuring the server-side setting to disable anonymous user registration only hides the client-side registration form. An attacker can still post registration data to create new accounts without prior authentication.
CVE-2021-43973
Last Modified: 21 Nov 2024An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to upload an arbitrary file via the file parameter in the HTTP POST body. A successful request returns the absolute, server-side filesystem path of the uploaded file.
CVE-2021-43972
Last Modified: 21 Nov 2024An unrestricted file copy vulnerability in /UserSelfServiceSettings.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to copy arbitrary files on the server filesystem to the web root (with an arbitrary filename) via the tempFile and fileName parameters in the HTTP POST body.
CVE-2021-43971
Last Modified: 21 Nov 2024A SQL injection vulnerability in /mobile/SelectUsers.jsp in SysAid ITIL 20.4.74 b10 allows a remote authenticated attacker to execute arbitrary SQL commands via the filterText parameter.
CVE-2021-1573
Last Modified: 11 Aug 2026A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
CVE-2021-34704
Last Modified: 11 Aug 2026A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to improper input validation when parsing HTTPS requests. An attacker could exploit this vulnerability by sending a malicious HTTPS request to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.
