IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2022-33645 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 2.2%
CVE-2022-33644 HIGH 7.0 microsoft windows_10 Xbox Live Save Service Elevation of Privilege Vulnerability 0.4%
CVE-2022-33643 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33642 MED 4.9 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 2.1%
CVE-2022-33641 MED 6.5 microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability 1.8%
CVE-2022-33640 HIGH 7.8 microsoft open_management_infrastructure System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability 0.6%
CVE-2022-33639 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.7%
CVE-2022-33638 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 2.4%
CVE-2022-33637 MED 6.5 microsoft defender_for_endpoint Microsoft Defender for Endpoint Tampering Vulnerability 1.6%
CVE-2022-33636 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.2%
CVE-2022-33635 HIGH 7.8 microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability 1.0%
CVE-2022-33634 HIGH 8.1 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 1.2%
CVE-2022-33633 HIGH 7.2 microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability 2.3%
CVE-2022-33632 MED 4.7 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 1.1%
CVE-2022-33631 HIGH 7.3 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 0.8%
CVE-2022-3344 MED 5.5 linux linux_kernel A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0). 0.2%
CVE-2022-33203 HIGH 7.5 f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when a BIG-IP APM access policy with Service Connect agent is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. 0.7%
CVE-2022-33158 HIGH 7.8 trendmicro vpn_proxy_one_pro Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some overly permissive folders in a key directory which could allow a local attacker to obtain privilege escalation on an affected system. 0.3%
CVE-2022-33140 HIGH 8.8 apache nifi The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUse 3.7%
CVE-2022-33127 CRIT 9.8 diffy_project diffy The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string. 1.8%
CVE-2022-3303 MED 4.7 debian debian_linux A race condition flaw was found in the Linux kernel sound subsystem due to improper locking. It could lead to a NULL pointer dereference while handling the SNDCTL_DSP_SYNC ioctl. A privileged local user (root or member of the audio group) could use this flaw t 0.3%
CVE-2022-32981 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER (aka PEEKUSR and POKEUSR) when accessing floating point registers. 1.0%
CVE-2022-32749 HIGH 7.5 apache traffic_server Improper Check for Unusual or Exceptional Conditions vulnerability handling requests in Apache Traffic Server allows an attacker to crash the server under certain conditions. This issue affects Apache Traffic Server: from 8.0.0 through 9.1.3. 1.3%
CVE-2022-32549 MED 5.3 apache sling_api Apache Sling Commons Log <= 5.4.0 and Apache Sling API <= 2.25.0 are vulnerable to log injection. The ability to forge logs may allow an attacker to cover tracks by injecting fake logs and potentially corrupt log files. 2.4%
CVE-2022-32533 CRIT 9.8 apache jetspeed Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dor 4.0%