57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-30142 | HIGH 7.5 | microsoft windows_10 Windows File History Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30141 | HIGH 8.1 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-30140 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-30139 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30138 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-30137 | MED 6.7 | microsoft service_fabric Executive Summary An Elevation of Privilege (EOP) vulnerability has been identified within Service Fabric clusters that run Docker containers. Exploitation of this EOP vulnerability requires an attacker to gain remote code execution within a container. All S | 1.1% | — |
| CVE-2022-30136 | CRIT 9.8 | microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability | 73.2% | — |
| CVE-2022-30135 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-30134 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 2.0% | — |
| CVE-2022-30133 | CRIT 9.8 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-30132 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-30131 | HIGH 7.8 | microsoft windows_server_2016 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-30130 | LOW 3.3 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 2.9% | — |
| CVE-2022-30129 | HIGH 8.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 41.3% | — |
| CVE-2022-30128 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2022-30127 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2022-30126 | MED 5.5 | apache tika In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtracting | 2.6% | — |
| CVE-2022-30055 | CRIT 9.8 | mersenne prime95 Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. | 3.9% | — |
| CVE-2022-29968 | HIGH 7.8 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. | 1.1% | — |
| CVE-2022-2991 | MED 6.7 | linux linux_kernel A heap-based buffer overflow was found in the Linux kernel's LightNVM subsystem. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. This vulnerability allows a local | 0.4% | — |
| CVE-2022-29901 | MED 5.6 | debian debian_linux Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary | 4.8% | — |
| CVE-2022-29885 | HIGH 7.5 | apache tomcat The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the | 73.5% | — |
| CVE-2022-29839 | MED 4.1 | westerndigital my_cloud_os Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affe | 0.1% | — |
| CVE-2022-29804 | HIGH 7.5 | golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. | 2.1% | — |
| CVE-2022-29800 | MED 4.7 | microsoft windows_defender_for_endpoint A time-of-check-time-of-use (TOCTOU) race condition vulnerability was found in networkd-dispatcher. This flaw exists because there is a certain time between the scripts being discovered and them being run. An attacker can abuse this vulnerability to replace sc | 7.2% | — |