CVE-2022-44678: Windows Print Spooler Elevation of Privilege Vulnerability
Windows Print Spooler Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Browse CVE records published in December 2022, with severity, affected products, CWE, KEV, and source-backed vulnerability context.
Showing 50 of 2503 matching CVEs · Page 10 of 51.
Windows Print Spooler Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Projected File System Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Bluetooth Driver Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Bluetooth Driver Information Disclosure Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Media Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Windows Media Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability
Published Dec 13, 2022 · Updated Jul 22, 2025
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. We recommend upgrading to version 2.0 and beyond.
Published Dec 1, 2022 · Updated Jun 18, 2025
A vulnerability was found in librespeed speedtest up to 5.2.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file results/stats.php. The manipulation of the argument id leads to cross site scripting. The attack can be launched remotely. Upgrading to version 5.2.5 is able to address this issue. The patch is named a85f2c086f3449dffa8fe2edb5e2ef3ee72dc0e9. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-246643.
Published Dec 3, 2023 · Updated Jun 3, 2025
A privilege escalation vulnerability exists in the sudo functionality of OpenStack Kolla git master 05194e7618. A misconfiguration in /etc/sudoers within a container can lead to increased privileges.
Published Dec 21, 2022 · Updated May 7, 2025
SQLite through 3.40.0, when relying on --safe for execution of an untrusted CLI script, does not properly implement the azProhibitedFunctions protection mechanism, and instead allows UDF functions such as WRITEFILE.
Published Dec 12, 2022 · Updated May 5, 2025
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
Published Dec 5, 2022 · Updated Apr 30, 2025
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this issue in https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32212 was incomplete and this new CVE is to complete the fix.
Published Dec 5, 2022 · Updated Apr 30, 2025
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes will) fail. 2) The random data returned byEntropySource() may not be cryptographically strong and therefore not suitable as keying material.
Published Dec 5, 2022 · Updated Apr 30, 2025
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
Published Dec 1, 2022 · Updated Apr 29, 2025
A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The title parameter on the twitter.php endpoint does not properly neutralise user input, resulting in the vulnerability.
Published Dec 1, 2022 · Updated Apr 25, 2025
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Published Dec 1, 2022 · Updated Apr 24, 2025
Symantec Endpoint Protection (Windows) agent, prior to 14.3 RU6/14.3 RU5 Patch 1, may be susceptible to a Security Control Bypass vulnerability, which is a type of issue that can potentially allow a threat actor to circumvent existing security controls. This CVE applies narrowly to the Client User Interface Password protection and Policy Import/Export Password protection, if it has been enabled.
Published Dec 1, 2022 · Updated Apr 24, 2025
ThinkCMF version 6.0.7 is affected by a Cross Site Request Forgery (CSRF) vulnerability that allows a Super Administrator user to be injected into administrative users.
Published Dec 1, 2022 · Updated Apr 24, 2025
ThinkCMF version 6.0.7 is affected by Stored Cross-Site Scripting (XSS). An attacker who successfully exploited this vulnerability could inject a Persistent XSS payload in the Slideshow Management section that execute arbitrary JavaScript code on the client side, e.g., to steal the administrator's PHP session token (PHPSESSID).
Published Dec 1, 2022 · Updated Apr 24, 2025
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/classes/Master.php?f=delete_product.
Published Dec 2, 2022 · Updated Apr 24, 2025
PC Keyboard WiFi & Bluetooth allows an attacker (in a man-in-the-middle position between the server and a connected device) to see all data (including keypresses) in cleartext. CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Published Dec 2, 2022 · Updated Apr 24, 2025
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
Published Dec 1, 2022 · Updated Apr 24, 2025
A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older than version 19.5 GA.
Published Dec 1, 2022 · Updated Apr 24, 2025
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Published Dec 1, 2022 · Updated Apr 24, 2025
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version 19.5 GA.
Published Dec 1, 2022 · Updated Apr 24, 2025
A path traversal vulnerability was addressed in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi which could allow an attacker to initiate installation of custom ZIP packages and overwrite system files. This could potentially lead to a code execution.
Published Dec 1, 2022 · Updated Apr 24, 2025
Incorrect default permissions in the installation folder for NI LabVIEW Command Line Interface (CLI) may allow an authenticated user to potentially enable escalation of privilege via local access.
Published Dec 1, 2022 · Updated Apr 24, 2025
Multiple Xiongmai NVR devices, including MBD6304T V4.02.R11.00000117.10001.131900.00000 and NBD6808T-PL V4.02.R11.C7431119.12001.130000.00000, allow authenticated users to execute arbitrary commands as root, as exploited in the wild starting in approximately 2019. A remote and authenticated attacker, possibly using the default admin:tlJwpbo6 credentials, can connect to port 34567 and execute arbitrary operating system commands via a crafted JSON file during an upgrade request. Since at least 2021, Xiongmai has applied patches to prevent attackers from using this mechanism to execute telnetd.
Published Dec 1, 2022 · Updated Apr 24, 2025
Tenda Tenda AC6V1.0 V15.03.05.19 is affected by buffer overflow. Causes a denial of service (local).
Published Dec 1, 2022 · Updated Apr 24, 2025
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
Published Dec 1, 2022 · Updated Apr 24, 2025
An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Published Dec 1, 2022 · Updated Apr 24, 2025
IBM Db2U 3.5, 4.0, and 4.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 237212.
Published Dec 1, 2022 · Updated Apr 24, 2025
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input.
Published Dec 2, 2022 · Updated Apr 24, 2025
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=quotes/view_quote&id=.
Published Dec 2, 2022 · Updated Apr 24, 2025
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/?page=inquiries/view_inquiry&id=.
Published Dec 2, 2022 · Updated Apr 24, 2025
Sanitization Management System v1.0 is vulnerable to SQL Injection via /php-sms/admin/orders/update_status.php?id=.
Published Dec 2, 2022 · Updated Apr 24, 2025
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule.
Published Dec 2, 2022 · Updated Apr 24, 2025
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo.
Published Dec 2, 2022 · Updated Apr 24, 2025
A cross-site scripting (XSS) vulnerability in Book Store Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the Add New System User module.
Published Dec 2, 2022 · Updated Apr 24, 2025
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php.
Published Dec 1, 2022 · Updated Apr 24, 2025
IXPdata EasyInstall 6.6.14725 contains an access control issue.
Published Dec 1, 2022 · Updated Apr 24, 2025
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1.
Published Dec 1, 2022 · Updated Apr 24, 2025
Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.
Published Dec 1, 2022 · Updated Apr 24, 2025
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
Published Dec 1, 2022 · Updated Apr 24, 2025
In GL.iNet Goodcloud 1.0, insecure design allows remote attacker to access devices' admin panel.
Published Dec 1, 2022 · Updated Apr 24, 2025
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the devName parameter in the formSetDeviceName function.
Published Dec 2, 2022 · Updated Apr 24, 2025
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind function.
Published Dec 2, 2022 · Updated Apr 24, 2025