58.061 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.061 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-24954 | CRIT 9.8 | foxit pdf_editor Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings. | 11.9% | — |
| CVE-2022-24948 | MED 6.1 | apache jspwiki A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information ab | 2.3% | — |
| CVE-2022-24947 | HIGH 8.8 | apache jspwiki Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later. | 1.2% | — |
| CVE-2022-24908 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.0% | — |
| CVE-2022-24907 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.0% | — |
| CVE-2022-24769 | MED 5.9 | debian debian_linux Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabiliti | 0.5% | — |
| CVE-2022-24767 | HIGH 7.8 | git_for_windows_project git_for_windows GitHub: Git for Windows' uninstaller vulnerable to DLL hijacking when run under the SYSTEM user account. | 1.5% | — |
| CVE-2022-24765 | MED 6.0 | apple xcode Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, w | 1.0% | — |
| CVE-2022-24760 | CRIT 10.0 | parseplatform parse-server Parse Server is an open source http web server backend. In versions prior to 4.10.7 there is a Remote Code Execution (RCE) vulnerability in Parse Server. This vulnerability affects Parse Server in the default configuration with MongoDB. The main weakness that | 49.1% | — |
| CVE-2022-24753 | HIGH 7.7 | stripe stripe_cli Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `stripe login`, `stripe config -e`, `stripe | 0.3% | — |
| CVE-2022-24697 | CRIT 9.8 | apache kylin Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any op | 84.8% | — |
| CVE-2022-24680 | HIGH 7.8 | trendmicro apex_one A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local at | 0.5% | — |
| CVE-2022-24679 | HIGH 7.8 | trendmicro apex_one A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local at | 0.5% | — |
| CVE-2022-24678 | HIGH 7.5 | trendmicro apex_one An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow an atta | 2.3% | — |
| CVE-2022-24550 | HIGH 7.8 | microsoft windows_10 Windows Telephony Server Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-24549 | HIGH 7.8 | microsoft windows_10 Windows AppX Package Manager Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-24548 | MED 5.5 | microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability | 3.0% | — |
| CVE-2022-24547 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 6.0% | — |
| CVE-2022-24546 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-24545 | HIGH 8.1 | microsoft windows_10 Windows Kerberos Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-24544 | HIGH 7.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-24543 | HIGH 7.8 | microsoft windows_upgrade_assistant Windows Upgrade Assistant Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-24542 | HIGH 7.8 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 9.2% | — |
| CVE-2022-24541 | HIGH 8.8 | microsoft windows_10 Windows Server Service Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2022-24540 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0.4% | — |