58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-23438 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) | 0.7% | — |
| CVE-2022-23437 | MED 6.5 | apache xerces-j There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged durati | 11.6% | — |
| CVE-2022-23307 | HIGH 8.8 | apache chainsaw CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | 54.4% | — |
| CVE-2022-23305 | CRIT 9.8 | apache log4j By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate | 66.5% | — |
| CVE-2022-23302 | HIGH 8.8 | apache log4j JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a Topi | 63.6% | — |
| CVE-2022-23301 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23300 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-2330 | MED 6.5 | mcafee data_loss_prevention_endpoint Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constr | 0.9% | — |
| CVE-2022-23299 | HIGH 7.8 | microsoft windows_10 Windows PDEV Elevation of Privilege Vulnerability | 7.6% | — |
| CVE-2022-23298 | HIGH 7.0 | microsoft windows_10 Windows NT OS Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23297 | MED 5.5 | microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-23296 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-23295 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23294 | HIGH 8.8 | microsoft windows_10 Windows Event Tracing Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23293 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-23292 | LOW 3.7 | microsoft on-premises_data_gateway Microsoft Power BI Spoofing Vulnerability | 0.8% | — |
| CVE-2022-23291 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23290 | HIGH 7.8 | microsoft windows_10 Windows Inking COM Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23288 | HIGH 7.0 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23287 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23286 | HIGH 7.0 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 4.3% | — |
| CVE-2022-23285 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 25.6% | — |
| CVE-2022-23284 | HIGH 7.2 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 3.2% | — |
| CVE-2022-23283 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-23282 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.4% | — |