58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-22721 | CRIT 9.1 | apache http_server If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. | 41.7% | — |
| CVE-2022-22720 | CRIT 9.8 | apache http_server Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling | 28.2% | — |
| CVE-2022-22719 | HIGH 7.5 | apache http_server A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. | 69.1% | — |
| CVE-2022-22717 | HIGH 7.0 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-22716 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 4.6% | — |
| CVE-2022-22715 | HIGH 7.8 | microsoft windows_10 Named Pipe File System Elevation of Privilege Vulnerability | 12.6% | — |
| CVE-2022-22713 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-22712 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.8% | — |
| CVE-2022-22711 | MED 5.7 | microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-22710 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability | 0.9% | — |
| CVE-2022-22709 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-22703 | MED 5.5 | stormshield network_security In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer. | 0.2% | — |
| CVE-2022-22528 | HIGH 7.8 | sap adaptive_server_enterprise SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privile | 0.3% | — |
| CVE-2022-22516 | HIGH 7.8 | codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | 0.3% | — |
| CVE-2022-22496 | MED 6.5 | ibm spectrum_protect_server While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942. | 0.4% | — |
| CVE-2022-22494 | MED 5.3 | ibm spectrum_protect_operations_center IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-F | 1.6% | — |
| CVE-2022-22493 | HIGH 8.8 | ibm websphere_automation_for_ibm_cloud_pak_for_watson_aiops IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. | 0.3% | — |
| CVE-2022-22490 | MED 4.9 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. | 0.8% | — |
| CVE-2022-22489 | CRIT 9.1 | ibm mq IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM | 1.7% | — |
| CVE-2022-22487 | CRIT 9.8 | ibm spectrum_protect_server An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using bru | 1.5% | — |
| CVE-2022-22485 | CRIT 9.8 | ibm spectrum_protect_operations_center In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this | 1.1% | — |
| CVE-2022-22484 | MED 5.5 | ibm spectrum_protect IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser histo | 0.2% | — |
| CVE-2022-22483 | MED 6.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979. | 1.1% | — |
| CVE-2022-22480 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889. | 0.8% | — |
| CVE-2022-22479 | HIGH 8.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. | 0.3% | — |