57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-37974 | MED 6.5 | microsoft windows_10 Windows Mixed Reality Developer Tools Information Disclosure Vulnerability | 36.3% | — |
| CVE-2022-37973 | HIGH 7.7 | microsoft windows_10 Windows Local Session Manager (LSM) Denial of Service Vulnerability | 2.9% | — |
| CVE-2022-37972 | HIGH 7.5 | microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability | 1.6% | — |
| CVE-2022-37971 | HIGH 7.1 | microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37970 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 9.8% | — |
| CVE-2022-37968 | CRIT 10.0 | microsoft azure_arc-enabled_kubernetes Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kub | 2.5% | — |
| CVE-2022-37967 | HIGH 7.2 | fedoraproject fedora Windows Kerberos Elevation of Privilege Vulnerability | 4.1% | — |
| CVE-2022-37966 | HIGH 8.1 | fedoraproject fedora Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-37965 | MED 5.9 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 1.5% | — |
| CVE-2022-37964 | HIGH 7.8 | microsoft windows_7 Windows Kernel Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-37963 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-37962 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2022-37961 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 50.7% | — |
| CVE-2022-37959 | MED 6.5 | microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2022-37958 | HIGH 8.1 | microsoft windows_10 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 86.0% | — |
| CVE-2022-37957 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 13.6% | — |
| CVE-2022-37956 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2022-37955 | HIGH 7.8 | microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-37954 | HIGH 7.8 | microsoft windows_10 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 44.9% | — |
| CVE-2022-37866 | HIGH 7.5 | apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" | 1.7% | — |
| CVE-2022-37865 | CRIT 9.1 | apache ivy With Apache Ivy 2.4.0 an optional packaging attribute has been introduced that allows artifacts to be unpacked on the fly if they used pack200 or zip packaging. For artifacts using the "zip", "jar" or "war" packaging Ivy prior to 2.5.1 doesn't verify the targe | 1.9% | — |
| CVE-2022-37771 | MED 6.7 | iobit malware_fighter IObit Malware Fighter v9.2 for Microsoft Windows lacks tamper protection, allowing authenticated attackers with Administrator privileges to modify processes within the application and escalate privileges to SYSTEM via a crafted executable. | 0.4% | — |
| CVE-2022-37436 | MED 5.3 | apache http_server Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by t | 61.0% | — |
| CVE-2022-37435 | HIGH 8.8 | apache shenyu Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3. | 1.3% | — |
| CVE-2022-37426 | MED 4.3 | opennebula opennebula Unrestricted Upload of File with Dangerous Type vulnerability in OpenNebula OpenNebula core on Linux allows File Content Injection. | 0.5% | — |