57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-44683 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 8.2% | — |
| CVE-2022-44682 | MED 6.8 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-44681 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44680 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44679 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-44678 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44677 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-44676 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-44675 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 5.0% | — |
| CVE-2022-44674 | MED 5.5 | microsoft windows_10 Windows Bluetooth Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-44673 | HIGH 7.0 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 5.2% | — |
| CVE-2022-44671 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-44670 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-44669 | HIGH 7.0 | microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-44668 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44667 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44666 | HIGH 7.8 | microsoft windows_10 Windows Contacts Remote Code Execution Vulnerability | 41.4% | — |
| CVE-2022-44650 | HIGH 7.8 | trendmicro apex_one A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ab | 0.4% | — |
| CVE-2022-44649 | HIGH 7.8 | trendmicro apex_one An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain th | 0.4% | — |
| CVE-2022-44648 | MED 5.5 | trendmicro apex_one An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged | 0.7% | — |
| CVE-2022-44647 | MED 5.5 | trendmicro apex_one An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged | 0.7% | — |
| CVE-2022-44645 | HIGH 8.8 | apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and maliciou | 1.9% | — |
| CVE-2022-44644 | MED 6.5 | apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the | 1.2% | — |
| CVE-2022-44635 | HIGH 8.8 | apache fineract Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and pr | 68.8% | — |
| CVE-2022-44621 | CRIT 9.8 | apache kylin Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. | 3.0% | — |