58.089 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.089 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-24288 | HIGH 8.8 | apache airflow In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI. | 77.9% | — |
| CVE-2022-24280 | MED 6.5 | apache pulsar Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to op | 1.3% | — |
| CVE-2022-24122 | HIGH 7.8 | fedoraproject fedora kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace. | 1.0% | — |
| CVE-2022-24113 | HIGH 7.8 | acronis agent Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Wind | 0.2% | — |
| CVE-2022-24105 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 2.3% | — |
| CVE-2022-24104 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th | 11.1% | — |
| CVE-2022-24103 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th | 3.5% | — |
| CVE-2022-24102 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th | 12.6% | — |
| CVE-2022-24101 | LOW 3.3 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to | 1.9% | — |
| CVE-2022-24099 | LOW 3.3 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Explo | 1.5% | — |
| CVE-2022-24098 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX file that could result in arbitrary code execution in the context of the current user. Exploitation of this issu | 2.6% | — |
| CVE-2022-24097 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.4% | — |
| CVE-2022-24096 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte | 3.9% | — |
| CVE-2022-24095 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte | 3.9% | — |
| CVE-2022-24094 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte | 3.9% | — |
| CVE-2022-24092 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation | 4.5% | — |
| CVE-2022-24091 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation | 4.1% | — |
| CVE-2022-24090 | MED 5.5 | adobe photoshop Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl | 2.0% | — |
| CVE-2022-24070 | HIGH 7.5 | apache subversion Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). | 9.5% | — |
| CVE-2022-23974 | HIGH 7.5 | apache pinot In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disru | 2.1% | — |
| CVE-2022-23945 | HIGH 7.5 | apache shenyu Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 3.8% | — |
| CVE-2022-23944 | CRIT 9.1 | apache shenyu User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 79.0% | — |
| CVE-2022-23943 | CRIT 9.8 | apache http_server Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. | 50.4% | — |
| CVE-2022-23942 | HIGH 7.5 | apache doris Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure. | 3.4% | — |
| CVE-2022-23913 | HIGH 7.5 | apache artemis In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory. | 2.7% | — |