58.251 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.251 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-21855 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-21852 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21851 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21850 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21849 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 6.2% | — |
| CVE-2022-21848 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 4.2% | — |
| CVE-2022-21847 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 1.0% | — |
| CVE-2022-21846 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-21845 | MED 4.7 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2022-21844 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-21843 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 3.4% | — |
| CVE-2022-21842 | HIGH 7.8 | microsoft sharepoint_enterprise_server Microsoft Word Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-21841 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-21840 | HIGH 8.8 | microsoft excel Microsoft Office Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2022-21839 | MED 6.1 | microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | 1.5% | — |
| CVE-2022-21838 | MED 5.5 | microsoft windows_10 Windows Cleanup Manager Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2022-21837 | HIGH 8.3 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2022-21836 | HIGH 7.8 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 0.7% | — |
| CVE-2022-21835 | HIGH 7.8 | microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21834 | HIGH 7.0 | microsoft windows_10 Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21833 | HIGH 7.8 | microsoft windows_10 Virtual Machine IDE Drive Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21827 | HIGH 7.1 | citrix gateway_plug-in An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt | 0.2% | — |
| CVE-2022-21825 | HIGH 7.8 | citrix workspace An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. | 0.2% | — |
| CVE-2022-21821 | HIGH 7.8 | nvidia cuda_toolkit NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an | 2.1% | — |
| CVE-2022-21820 | MED 6.3 | nvidia data_center_gpu_manager NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data conf | 16.5% | — |