Reference material - not professional advice. Test in staging, back up first, verify against your specific version. Use your own judgment for your environment.
Showing 130 of 130 guides from 2022
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in redis

CVE-2022-0543 is a remote code execution flaw in redis. Verified patched version and mitigations from the official advisory.

CVE-2022-0543 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in Sophos Firewall

CVE-2022-1040 is a vulnerability in Sophos Firewall. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-1040 · OtherRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix F5 BIG-IP iControl REST Unauthenticated Command Execution

CVE-2022-1388 is the F5 BIG-IP iControl REST auth bypass that gives root command execution. Patched builds and TMUI lockdown for emergency m

CVE-2022-1388 · F5Read fix →
CRITICAL⚠ KEVRCE

How to Fix Cisco RV340 SSL VPN Unauthenticated RCE

CVE-2022-20699 is the SSL VPN RCE in the Cisco RV Series bundle. Public exploit code exists. Patch or replace the hardware.

CVE-2022-20699 · CiscoRead fix →
CRITICAL⚠ KEV

How to Fix Cisco RV Series Router (Bundle Sibling)

CVE-2022-20700 is part of the Cisco RV160/RV260/RV340/RV345 bundle. Same advisory and same fix as CVE-2022-20708.

CVE-2022-20700 · CiscoRead fix →
CRITICAL⚠ KEV

How to Fix Cisco RV Series Router (Bundle Sibling)

CVE-2022-20701 is part of the Cisco RV160/RV260/RV340/RV345 bundle. Same advisory and same fix as CVE-2022-20708.

CVE-2022-20701 · CiscoRead fix →
CRITICAL⚠ KEV

How to Fix Cisco RV Series Router (Bundle Sibling)

CVE-2022-20703 is part of the Cisco RV160/RV260/RV340/RV345 bundle. Same advisory and same fix as CVE-2022-20708.

CVE-2022-20703 · CiscoRead fix →
CRITICAL⚠ KEVBuffer Overflow

How to Fix Cisco RV Series Router Stack Buffer Overflow

CVE-2022-20708 is part of the unpatched Cisco RV160/RV260/RV340/RV345 bundle. Mitigation steps and the end-of-life reality.

CVE-2022-20708 · CiscoRead fix →
CRITICAL⚠ KEVDeserialization

How to Fix Insecure Deserialization in Application Development Framework (ADF)

CVE-2022-21445 - Insecure Deserialization in Application Development Framework (ADF). Runnable patch commands and verification on this page.

CVE-2022-21445 · OracleRead fix →
CRITICAL⚠ KEVRCE

How to Fix Oracle Web Applications Desktop Integrator Unauthenticated RCE

CVE-2022-21587 lets unauthenticated attackers run code via Oracle Web Applications Desktop Integrator in E-Business Suite. Critical Patch Up

CVE-2022-21587 · OracleRead fix →
CRITICAL⚠ KEV

How to Fix HTTP Request Smuggling in SAP Content Server, SAP NetWeaver and ABAP Platform, SAP Web Dispatcher

CVE-2022-22536 is a http request smuggling flaw in SAP Content Server, SAP NetWeaver and ABAP Platform, SAP Web Dispatcher. Verified patched

CVE-2022-22536 · SapRead fix →
CRITICAL⚠ KEVDoS

How to Fix Denial of Service in iOS and iPadOS, macOS

CVE-2022-22587 is a denial of service flaw in iOS and iPadOS, macOS. Verified patched version and mitigations from the official advisory.

CVE-2022-22587 · AppleRead fix →
CRITICAL⚠ KEV

How to Fix Improper Control of Generation of Code ('Code Injection' in Spring Cloud Gateway

Improper Control of Generation of Code ('Code Injection' in Spring Cloud Gateway (VMware). Actively exploited. Verified patched versions and

CVE-2022-22947 · VmwareRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in VMware Workspace ONE Access and Identity Manager

Remote Code Execution in VMware Workspace ONE Access and Identity Manager. Actively exploited. Verified patched versions and remediation ste

CVE-2022-22954 · VmwareRead fix →
CRITICAL⚠ KEV

How to Fix Code Injection in Spring Cloud Function

CVE-2022-22963 is a code injection flaw in Spring Cloud Function. Verified patched version and mitigations from the official advisory.

CVE-2022-22963 · VmwareRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Spring Framework

Remote Code Execution in Spring Framework (VMware). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-22965 · VmwareRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Authentication Bypass in Frontend

CVE-2022-23131 is an authentication bypass in Frontend. Verified patched version, official vendor advisory, and how to confirm the fix lande

CVE-2022-23131 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in NUUO NVRmini2 through

CVE-2022-23227 is a security vulnerability flaw in NUUO NVRmini2 through. Verified patched version and mitigations from the official advisor

CVE-2022-23227 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Adobe Commerce / Magento Improper Input Validation

CVE-2022-24086 is the Adobe Commerce / Magento improper input validation that gives unauthenticated RCE. Apply APSB22-12 hotfix and rotate M

CVE-2022-24086 · AdobeRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Authentication Bypass by Spoofing in Apache APISIX

CVE-2022-24112 is an authentication bypass by spoofing flaw in Apache APISIX. Verified patched version and mitigations from the official adv

CVE-2022-24112 · ApacheRead fix →
CRITICAL⚠ KEV

How to Fix Insecure Default Initialization in Apache CouchDB

CVE-2022-24706 is an insecure default initialization flaw in Apache CouchDB. Verified patched version and mitigations from the official advi

CVE-2022-24706 · ApacheRead fix →
CRITICAL⚠ KEVRCE

How to Fix Code Injection RCE in jai-ext

CVE-2022-24816 is a code injection in jai-ext. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-24816 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in TerraMaster NAS

CVE-2022-24990 is a security vulnerability flaw in TerraMaster NAS. Verified patched version and mitigations from the official advisory.

CVE-2022-24990 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Confluence Data Center, Confluence Server

CVE-2022-26134 is a security vulnerability flaw in Confluence Data Center, Confluence Server. Verified patched version and mitigations from

CVE-2022-26134 · AtlassianRead fix →
CRITICAL⚠ KEV

How to Fix Hardcoded Credentials in Questions For Confluence

CVE-2022-26138 is a hardcoded credentials flaw in Questions For Confluence. Verified patched version and mitigations from the official advis

CVE-2022-26138 · AtlassianRead fix →
CRITICAL⚠ KEVDoS

How to Fix Denial of Service in MiCollab, MiVoice Business Express

Denial of Service in MiCollab, MiVoice Business Express (Mitel). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-26143 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in DIR-820L

CVE-2022-26258 is a remote code execution flaw in DIR-820L. Verified patched version and mitigations from the official advisory.

CVE-2022-26258 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Firebox and XTM Appliances

Security Vulnerability in Firebox and XTM Appliances (WatchGuard). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-26318 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in dotCMS

CVE-2022-26352 is a remote code execution flaw in dotCMS. Verified patched version and mitigations from the official advisory.

CVE-2022-26352 · OtherRead fix →
CRITICAL⚠ KEVUse After Free

How to Fix Use-After-Free in Firefox

Use-After-Free in Firefox (Mozilla). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-26486 · FirefoxRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Backup & Replication

CVE-2022-26501 is a security vulnerability flaw in Backup & Replication. Verified patched version and mitigations from the official advisory

CVE-2022-26501 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Trend Micro Apex Central

CVE-2022-26871 is a remote code execution flaw in Trend Micro Apex Central. Verified patched version and mitigations from the official advis

CVE-2022-26871 · Trend MicroRead fix →
CRITICAL⚠ KEVRCE

How to Fix Citrix ADC and Gateway Unauthenticated RCE (APT5)

CVE-2022-27518 is the Citrix ADC / Gateway zero-day exploited by APT5 against defense contractors in 2022. Patched builds and SAML configura

CVE-2022-27518 · CitrixRead fix →
CRITICAL⚠ KEVSSRF

How to Fix SSRF Vulnerability in Photo Station

CVE-2022-27593: a server-side request forgery (SSRF) in Photo Station. Patched version and vendor advisory inside.

CVE-2022-27593 · QnapRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in Compact

CVE-2022-29303 is a command injection flaw in Compact. Verified patched version and mitigations from the official advisory.

CVE-2022-29303 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in n/a

CVE-2022-29464 is a vulnerability in n/a. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-29464 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in MiVoice Connect

CVE-2022-29499 is a remote code execution flaw in MiVoice Connect. Verified patched version and mitigations from the official advisory.

CVE-2022-29499 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in USG FLEX 100(W) firmware

CVE-2022-30525: an OS command injection in USG FLEX 100(W) firmware. Patched version and vendor advisory inside.

CVE-2022-30525 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Chrome

CVE-2022-3075 is a security vulnerability flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-3075 · GoogleRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Auditor

CVE-2022-31199 is a remote code execution flaw in Auditor. Verified patched version and mitigations from the official advisory.

CVE-2022-31199 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Critical Vulnerability in Sophos Firewall

CVE-2022-3236 is a vulnerability in Sophos Firewall. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-3236 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Zoho ManageEngine Password Manager Pro

CVE-2022-35405 is a remote code execution flaw in Zoho ManageEngine Password Manager Pro. Verified patched version and mitigations from the

CVE-2022-35405 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in GLPI

CVE-2022-35914 is a security vulnerability flaw in GLPI. Verified patched version and mitigations from the official advisory.

CVE-2022-35914 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Zimbra Collaboration Suite (ZCS)

CVE-2022-37042 is a remote code execution flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the offici

CVE-2022-37042 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Memory Corruption in Routers

CVE-2022-37055 is a memory corruption flaw in Routers. Verified patched version and mitigations from the official advisory.

CVE-2022-37055 · OtherRead fix →
CRITICAL⚠ KEVAuth Bypass

How to Fix Fortinet FortiOS/FortiProxy/FortiSwitchManager Auth Bypass

CVE-2022-40684 lets unauthenticated attackers bypass admin authentication on Fortinet appliances. Public exploit code exists. Patch and lock

CVE-2022-40684 · FortinetRead fix →
CRITICAL⚠ KEV

How to Fix Memory Corruption in Chrome

CVE-2022-4135 is a memory corruption flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-4135 · GoogleRead fix →
CRITICAL⚠ KEVPath Traversal

How to Fix Path Traversal in Zimbra Collaboration Suite (ZCS)

CVE-2022-41352 is a path traversal flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the official advi

CVE-2022-41352 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Memory Corruption in FortiProxy

CVE-2022-42475 is a memory corruption in FortiProxy. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-42475 · FortinetRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in Cobalt Strike

CVE-2022-42948 is a remote code execution flaw in Cobalt Strike. Verified patched version and mitigations from the official advisory.

CVE-2022-42948 · OtherRead fix →
CRITICAL⚠ KEV

How to Fix Security Vulnerability in Control Web Panel

CVE-2022-44877 is a security vulnerability flaw in Control Web Panel. Verified patched version and mitigations from the official advisory.

CVE-2022-44877 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Command Injection in cacti

CVE-2022-46169 is an OS command injection in cacti. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-46169 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix Remote Code Execution in ManageEngine

CVE-2022-47966 is a remote code execution flaw in ManageEngine. Verified patched version and mitigations from the official advisory.

CVE-2022-47966 · OtherRead fix →
CRITICAL⚠ KEVRCE

How to Fix IBM Aspera Faspex YAML Deserialization RCE

CVE-2022-47986 is the IBM Aspera Faspex YAML deserialization that gives unauthenticated RCE. IceFire ransomware used it. Patched version and

CVE-2022-47986 · IbmRead fix →
HIGH⚠ KEVDoS

How to Fix Denial of Service in Cloud NGFW

CVE-2022-0028 is a denial of service in Cloud NGFW. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-0028 · Palo AltoRead fix →
HIGH⚠ KEV

How to Fix Integer Overflow in kernel

CVE-2022-0185 is an integer overflow flaw in kernel. Verified patched version and mitigations from the official advisory.

CVE-2022-0185 · LinuxRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Chrome

CVE-2022-0609 is an use-after-free flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-0609 · GoogleRead fix →
HIGH⚠ KEV

How to Fix ->CWE-281 in kernel

->CWE-281 in kernel (Linux). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-0847 · LinuxRead fix →
HIGH⚠ KEV

How to Fix Type Confusion in Chrome

CVE-2022-1096 is a type confusion flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-1096 · GoogleRead fix →
HIGH⚠ KEV

How to Fix Type Confusion in Chrome

CVE-2022-1364 is a type confusion flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-1364 · GoogleRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in Cisco Catalyst SD-WAN

CVE-2022-20775 is a path traversal in Cisco Catalyst SD-WAN. Verified patched version, official vendor advisory, and how to confirm the fix

CVE-2022-20775 · CiscoRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds write in Microsoft Windows

CVE-2022-21882 is an out-of-bounds write in Microsoft Windows. This page lists verified fix commands and short-term mitigations you can run

CVE-2022-21882 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Improper Link Resolution Before File Access in Microsoft Windows

CVE-2022-21919: Improper Link Resolution Before File Access in Microsoft Windows. Runnable fix commands and patched builds.

CVE-2022-21919 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Access of Uninitialized Pointer in Windows 10 Version 1809

CVE-2022-21971 access of uninitialized pointer in Windows 10 Version 1809. Runnable upgrade commands and verification steps for sysadmins.

CVE-2022-21971 · MicrosoftRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in Microsoft Windows

CVE-2022-21999 is a Path Traversal flaw in Microsoft Windows. Actively exploited per CISA KEV. Verified patched builds and runnable fix comm

CVE-2022-21999 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Untrusted Search Path in Windows 10 Version 1809

CVE-2022-22047 is a untrusted search path in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2022-22047 · MicrosoftRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Qualcomm, Inc. Snapdragon Auto

CVE-2022-22071 is a Use-After-Free flaw in Qualcomm, Inc. Snapdragon Auto. Actively exploited per CISA KEV. Verified patched builds and fix

CVE-2022-22071 · GoRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Safari (v and ), macOS

CVE-2022-22620 is a remote code execution flaw in Safari (v and ), macOS. Verified patched version and mitigations from the official advisor

CVE-2022-22620 · AppleRead fix →
HIGH⚠ KEVDoS

How to Fix Denial of Service in iOS and iPadOS, macOS, watchOS

CVE-2022-22675 is a denial of service flaw in iOS and iPadOS, macOS, watchOS. Verified patched version and mitigations from the official adv

CVE-2022-22675 · AppleRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Arm Mali GPU Kernel Driver

CVE-2022-22706 is a security vulnerability flaw in Arm Mali GPU Kernel Driver. Verified patched version and mitigations from the official ad

CVE-2022-22706 · OtherRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Elevation of Privilege in Microsoft Windows

CVE-2022-22718 is a Elevation of Privilege flaw in Microsoft Windows. Actively exploited per CISA KEV. Verified patched builds and runnable

CVE-2022-22718 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Memory Corruption in Chrome

CVE-2022-2294 is a memory corruption flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-2294 · GoogleRead fix →
HIGH⚠ KEVPrivilege Escalation

How to Fix Privilege Escalation in VMware Workspace ONE Access

Privilege Escalation in VMware Workspace ONE Access. Actively exploited. Verified patched versions and remediation steps.

CVE-2022-22960 · VmwareRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Firebox and XTM

Security Vulnerability in Firebox and XTM (WatchGuard). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-23176 · OtherRead fix →
HIGH⚠ KEV

How to Fix Process Control in Audinate Dante Application Library for Windows

CVE-2022-23748 is a process control flaw in Audinate Dante Application Library for Windows. Verified patched version and mitigations from th

CVE-2022-23748 · WindowsRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-Bounds Write in Microsoft Windows

CVE-2022-24521 is a Out-of-Bounds Write flaw in Microsoft Windows. Actively exploited per CISA KEV. Verified patched builds and runnable fix

CVE-2022-24521 · MicrosoftRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Firefox

Use-After-Free in Firefox (Mozilla). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-26485 · FirefoxRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Backup & Replication

CVE-2022-26500 is a security vulnerability flaw in Backup & Replication. Verified patched version and mitigations from the official advisory

CVE-2022-26500 · OtherRead fix →
HIGH⚠ KEV

How to Fix Race Condition in Microsoft Windows

CVE-2022-26904 is a Race Condition flaw in Microsoft Windows. Actively exploited per CISA KEV. Verified patched builds and runnable fix comm

CVE-2022-26904 · MicrosoftRead fix →
HIGH⚠ KEVCrypto Weak

How to Fix Improper Certificate Validation in Windows 10 Version 1809

CVE-2022-26923 improper certificate validation in Windows 10 Version 1809. Runnable upgrade commands and verification steps for sysadmins.

CVE-2022-26923 · MicrosoftRead fix →
HIGH⚠ KEVAuth Bypass

How to Fix Missing Authentication for Critical Function in Windows 10 Version 1809

CVE-2022-26925 missing authentication for critical function in Windows 10 Version 1809. Runnable upgrade commands and verification steps for

CVE-2022-26925 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Zimbra Collaboration Suite (ZCS)

CVE-2022-27924 is a security vulnerability flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the offic

CVE-2022-27924 · OtherRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in Zimbra Collaboration Suite (ZCS)

CVE-2022-27925 is a path traversal flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the official advi

CVE-2022-27925 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Windows 10 Version 1809

CVE-2022-30190 is a remote code execution in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2022-30190 · MicrosoftRead fix →
HIGH⚠ KEVPath Traversal

How to Fix Path Traversal in RARLAB UnRAR

CVE-2022-30333 is a path traversal flaw in RARLAB UnRAR. Verified patched version and mitigations from the official advisory.

CVE-2022-30333 · OtherRead fix →
HIGH⚠ KEVUse After Free

How to Fix Use-After-Free in Chrome

CVE-2022-3038 is an use-after-free flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-3038 · GoogleRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Safari, iOS and iPadOS, macOS

CVE-2022-32893 is a remote code execution flaw in Safari, iOS and iPadOS, macOS. Verified patched version and mitigations from the official

CVE-2022-32893 · AppleRead fix →
HIGH⚠ KEVDoS

How to Fix Denial of Service in iOS and iPadOS, macOS

CVE-2022-32894 is a denial of service flaw in iOS and iPadOS, macOS. Verified patched version and mitigations from the official advisory.

CVE-2022-32894 · AppleRead fix →
HIGH⚠ KEVDoS

How to Fix Denial of Service in iOS, macOS

CVE-2022-32917 is a denial of service flaw in iOS, macOS. Verified patched version and mitigations from the official advisory.

CVE-2022-32917 · AppleRead fix →
HIGH⚠ KEVRCE

How to Fix OS Command Injection in Apache Spark

CVE-2022-33891 is an os command injection flaw in Apache Spark. Verified patched version and mitigations from the official advisory.

CVE-2022-33891 · ApacheRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Windows 10 Version 1809

CVE-2022-34713 is a remote code execution in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2022-34713 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in ZK Framework

CVE-2022-36537 is a security vulnerability flaw in ZK Framework. Verified patched version and mitigations from the official advisory.

CVE-2022-36537 · OtherRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Bitbucket Data Center, Bitbucket Server

CVE-2022-36804 is a security vulnerability flaw in Bitbucket Data Center, Bitbucket Server. Verified patched version and mitigations from th

CVE-2022-36804 · AtlassianRead fix →
HIGH⚠ KEV

How to Fix Type Confusion in Chrome

CVE-2022-3723 is a type confusion flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-3723 · GoogleRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds Write in Windows 10 Version 1809

CVE-2022-37969 is a out-of-bounds write in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix la

CVE-2022-37969 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2022-38028 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2022-38028 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in The Arm Mali GPU kernel driver

CVE-2022-38181 is a security vulnerability flaw in The Arm Mali GPU kernel driver. Verified patched version and mitigations from the officia

CVE-2022-38181 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in Trend Micro Apex One

CVE-2022-40139 is a remote code execution flaw in Trend Micro Apex One. Verified patched version and mitigations from the official advisory.

CVE-2022-40139 · Trend MicroRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in DNR-322L

CVE-2022-40799 is a security vulnerability flaw in DNR-322L. Verified patched version and mitigations from the official advisory.

CVE-2022-40799 · OtherRead fix →
HIGH⚠ KEVRCE

How to Fix Access of Resource Using Incompatible Type ('Type Confusion')

CVE-2022-41033 access of resource using incompatible type ('type confusion') in Windows 10 Version 1809. Runnable upgrade commands and verif

CVE-2022-41033 · MicrosoftRead fix →
HIGH⚠ KEVSSRF

How to Fix Server-Side Request Forgery (SSRF)

CVE-2022-41040 server-side request forgery (ssrf) in Microsoft Exchange Server 2013 Cumulative Update 23. Runnable upgrade commands and veri

CVE-2022-41040 · MicrosoftRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds Write in Windows 10 Version 1809

CVE-2022-41073 is a out-of-bounds write in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix la

CVE-2022-41073 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Security Vulnerability in Microsoft Exchange Server 2016 Cumulative Update 23

CVE-2022-41080 security vulnerability in Microsoft Exchange Server 2016 Cumulative Update 23. Runnable upgrade commands and verification ste

CVE-2022-41080 · MicrosoftRead fix →
HIGH⚠ KEVDeserialization

How to Fix Deserialization of Untrusted Data

CVE-2022-41082 deserialization of untrusted data in Microsoft Exchange Server 2013 Cumulative Update 23. Runnable upgrade commands and verif

CVE-2022-41082 · MicrosoftRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds Write in Windows 10 Version 1809

CVE-2022-41125 is a out-of-bounds write in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix la

CVE-2022-41125 · MicrosoftRead fix →
HIGH⚠ KEVBuffer Overflow

How to Fix Out-of-bounds Write in Windows 10 Version 1809

CVE-2022-41128 is a out-of-bounds write in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix la

CVE-2022-41128 · MicrosoftRead fix →
HIGH⚠ KEV

How to Fix Type Confusion in Chrome

CVE-2022-4262 is a type confusion flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-4262 · GoogleRead fix →
HIGH⚠ KEVDoS

How to Fix Denial of Service in iOS and iPadOS

CVE-2022-42827 is a denial of service flaw in iOS and iPadOS. Verified patched version and mitigations from the official advisory.

CVE-2022-42827 · AppleRead fix →
HIGH⚠ KEVRCE

How to Fix Remote Code Execution in tvOS

CVE-2022-42856 is a remote code execution flaw in tvOS. Verified patched version and mitigations from the official advisory.

CVE-2022-42856 · AppleRead fix →
HIGH⚠ KEV

How to Fix Critical Vulnerability in Pentaho Business Analytics Server

CVE-2022-43769: a vulnerability in Pentaho Business Analytics Server. Patched version and vendor advisory inside.

CVE-2022-43769 · OtherRead fix →
HIGH⚠ KEV

How to Fix Use of Non-Canonical URL Paths for Authorization Decisions in Hitachi Vantara Pentaho Business Analytics Server

CVE-2022-43939: Use of Non-Canonical URL Paths for Authorization Decisions in Hitachi Vantara Pentaho Business Analytics Server. Patched bui

CVE-2022-43939 · OtherRead fix →
MEDIUM⚠ KEVInfo Disclosure

How to Fix Information Disclosure in Cisco IOS XR Software

CVE-2022-20821: an information disclosure in Cisco IOS XR Software. Patched version and vendor advisory inside.

CVE-2022-20821 · CiscoRead fix →
MEDIUM⚠ KEV

How to Fix Samsung Mobile Samsung Mobile Devices (Bundle Sibling)

CVE-2022-22265: Improper Check or Handling of Exceptional Conditions in Samsung Mobile Samsung Mobile Devices. Patched builds and fix steps.

CVE-2022-22265 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix Memory Corruption in macOS

CVE-2022-22674 is a memory corruption flaw in macOS. Verified patched version and mitigations from the official advisory.

CVE-2022-22674 · AppleRead fix →
MEDIUM⚠ KEVInfo Disclosure

How to Fix Information Disclosure in VMware vCenter Server and VMware Cloud Foundation

CVE-2022-22948 is an information disclosure flaw in VMware vCenter Server and VMware Cloud Foundation. Verified patched version and mitigati

CVE-2022-22948 · VmwareRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Zimbra Collaborate Suite (ZCS)

Security Vulnerability in Zimbra Collaborate Suite (ZCS) (Synacor). Actively exploited. Verified patched versions and remediation steps.

CVE-2022-24682 · OtherRead fix →
MEDIUM⚠ KEVUse After Free

How to Fix Use-After-Free in The Linux Kernel Organization linux

CVE-2022-2586 is a Use-After-Free flaw in The Linux Kernel Organization linux. Actively exploited per CISA KEV. Verified patched builds and

CVE-2022-2586 · LinuxRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Zimbra Collaboration Suite (ZCS)

CVE-2022-27926 is a cross-site scripting flaw in Zimbra Collaboration Suite (ZCS). Verified patched version and mitigations from the officia

CVE-2022-27926 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Chrome

CVE-2022-2856 is a security vulnerability flaw in Chrome. Verified patched version and mitigations from the official advisory.

CVE-2022-2856 · GoogleRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Zoho ManageEngine ADSelfService Plus

CVE-2022-28810 is a security vulnerability flaw in Zoho ManageEngine ADSelfService Plus. Verified patched version and mitigations from the o

CVE-2022-28810 · OtherRead fix →
MEDIUM⚠ KEVXSS

How to Fix Cross-Site Scripting in Cobalt Strike

CVE-2022-39197 is a cross-site scripting flaw in Cobalt Strike. Verified patched version and mitigations from the official advisory.

CVE-2022-39197 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in MiVoice Connect

CVE-2022-40765 is a security vulnerability flaw in MiVoice Connect. Verified patched version and mitigations from the official advisory.

CVE-2022-40765 · OtherRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2022-41049 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2022-41049 · MicrosoftRead fix →
MEDIUM⚠ KEV

How to Fix Incorrect Authorization in Windows 10 Version 1809

CVE-2022-41091 is a incorrect authorization in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fi

CVE-2022-41091 · MicrosoftRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in MiVoice Connect

CVE-2022-41223 is a security vulnerability flaw in MiVoice Connect. Verified patched version and mitigations from the official advisory.

CVE-2022-41223 · OtherRead fix →
MEDIUM⚠ KEVPath Traversal

How to Fix Path Traversal in FortiOS

CVE-2022-41328 is a path traversal in FortiOS. Verified patched version, official vendor advisory, and how to confirm the fix landed.

CVE-2022-41328 · FortinetRead fix →
MEDIUM⚠ KEV

How to Fix Security Vulnerability in Windows 10 Version 1809

CVE-2022-44698 is a security vulnerability in Windows 10 Version 1809. Patched version, runnable upgrade commands, and how to verify the fix

CVE-2022-44698 · MicrosoftRead fix →
LOW⚠ KEV

How to Fix Improper Access Control in Zabbix Frontend

CVE-2022-23134 is a Improper Access Control flaw in Zabbix Frontend. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2022-23134 · OtherRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple Safari

CVE-2022-48503 is a Denial of Service flaw in Apple Safari. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2022-48503 · AppleRead fix →
NOT VERIFIED⚠ KEVDoS

How to Fix Denial of Service in Apple iOS and iPadOS

CVE-2022-48618 is a Denial of Service flaw in Apple iOS and iPadOS. Actively exploited per CISA KEV. Verified patched builds and fix steps.

CVE-2022-48618 · AppleRead fix →