57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-41331 | CRIT 9.8 | fortinet fortiproxy A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, unauthenticated attacker to access the Redis and MongoDB instances via crafted authentication requests. | 1.3% | — |
| CVE-2022-41330 | HIGH 8.8 | fortinet fortios An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7 | 0.6% | — |
| CVE-2022-41329 | MED 5.3 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to | 0.6% | — |
| CVE-2022-41327 | HIGH 7.8 | fortinet fortios A cleartext transmission of sensitive information vulnerability [CWE-319] in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.8, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.8 allows an authenticated attacker with readonly supera | 0.1% | — |
| CVE-2022-41294 | MED 6.5 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | 0.3% | — |
| CVE-2022-41291 | MED 6.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. | 0.4% | — |
| CVE-2022-4128 | MED 5.5 | linux linux_kernel A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service. | 0.2% | — |
| CVE-2022-4127 | MED 5.5 | linux linux_kernel A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service. | 0.2% | — |
| CVE-2022-41261 | MED 6.0 | sap solution_manager SAP Solution Manager (Diagnostic Agent) - version 7.20, allows an authenticated attacker on Windows system to access a file containing sensitive data which can be used to access a configuration file which contains credentials to access other system files. Succ | 0.2% | — |
| CVE-2022-4126 | CRIT 9.6 | abb rccmd Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207. | 0.6% | — |
| CVE-2022-41222 | HIGH 7.0 | canonical ubuntu_linux mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move. | 0.5% | — |
| CVE-2022-41218 | MED 5.5 | debian debian_linux In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release. | 0.8% | — |
| CVE-2022-41205 | MED 5.5 | sap gui SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application. | 0.2% | — |
| CVE-2022-41158 | HIGH 7.2 | eyoom eyoom_builder Remote code execution vulnerability can be achieved by using cookie values as paths to a file by this builder program. A remote attacker could exploit the vulnerability to execute or inject malicious code. | 1.9% | — |
| CVE-2022-41157 | HIGH 8.1 | webcash serp_server_2.0 A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. | 0.5% | — |
| CVE-2022-41156 | HIGH 7.8 | etm-s ondiskplayeragent Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attacker could exploit the vulnerability to cause remote code execution by causing an arbitrary user to download and execute malicious code. | 0.2% | — |
| CVE-2022-41137 | HIGH 8.3 | apache hive Apache Hive Metastore (HMS) uses SerializationUtilities#deserializeObjectWithTypeInformation method when filtering and fetching partitions that is unsafe and can lead to Remote Code Execution (RCE) since it allows the deserialization of arbitrary data. In rea | 1.6% | — |
| CVE-2022-41131 | HIGH 7.8 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Hive Provider, Apache Airflow allows an attacker to execute arbtrary commands in the task execution context, without write access to DAG | 1.8% | — |
| CVE-2022-41127 | HIGH 8.5 | microsoft dynamics_365_business_central Microsoft Dynamics NAV and Microsoft Dynamics 365 Business Central (On Premises) Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-41123 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-41122 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.6% | — |
| CVE-2022-41121 | HIGH 7.8 | microsoft powershell Windows Graphics Component Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-41120 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-41119 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41118 | HIGH 7.5 | microsoft windows_10 Windows Scripting Languages Remote Code Execution Vulnerability | 1.1% | — |