IT
58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-22721 CRIT 9.1 apache http_server If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. 41.7%
CVE-2022-22720 CRIT 9.8 apache http_server Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling 28.2%
CVE-2022-22719 HIGH 7.5 apache http_server A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. 69.1%
CVE-2022-22717 HIGH 7.0 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7%
CVE-2022-22716 MED 5.5 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 4.6%
CVE-2022-22715 HIGH 7.8 microsoft windows_10 Named Pipe File System Elevation of Privilege Vulnerability 12.6%
CVE-2022-22713 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.7%
CVE-2022-22712 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.8%
CVE-2022-22711 MED 5.7 microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability 0.5%
CVE-2022-22710 MED 5.5 microsoft windows_10 Windows Common Log File System Driver Denial of Service Vulnerability 0.9%
CVE-2022-22709 HIGH 7.8 microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability 2.3%
CVE-2022-22703 MED 5.5 stormshield network_security In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer. 0.2%
CVE-2022-22528 HIGH 7.8 sap adaptive_server_enterprise SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privile 0.3%
CVE-2022-22516 HIGH 7.8 codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. 0.3%
CVE-2022-22496 MED 6.5 ibm spectrum_protect_server While a user account for the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 is being established, it may be configured to use SESSIONSECURITY=TRANSITIONAL. While in this mode, it may be susceptible to an offline dictionary attack. IBM X-Force ID: 226942. 0.4%
CVE-2022-22494 MED 5.3 ibm spectrum_protect_operations_center IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-F 1.6%
CVE-2022-22493 HIGH 8.8 ibm websphere_automation_for_ibm_cloud_pak_for_watson_aiops IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. 0.3%
CVE-2022-22490 MED 4.9 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a privileged user to obtain sensitive Azure bot credential information. IBM X-Force ID: 226342. 0.8%
CVE-2022-22489 CRIT 9.1 ibm mq IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM 1.7%
CVE-2022-22487 CRIT 9.8 ibm spectrum_protect_server An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using bru 1.5%
CVE-2022-22485 CRIT 9.8 ibm spectrum_protect_operations_center In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this 1.1%
CVE-2022-22484 MED 5.5 ibm spectrum_protect IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By accessing browser histo 0.2%
CVE-2022-22483 MED 6.5 ibm db2 IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an information disclosure in some scenarios due to unauthorized access caused by improper privilege management when CREATE OR REPLACE command is used. IBM X-Force ID: 225979. 1.1%
CVE-2022-22480 HIGH 7.5 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5 data node rebalancing does not function correctly when using encrypted hosts which could result in information disclosure. IBM X-Force ID: 225889. 0.8%
CVE-2022-22479 HIGH 8.8 ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. 0.3%