58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-2049 | HIGH 7.5 | octopus octopus_server In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function. | 0.7% | — |
| CVE-2022-2013 | HIGH 7.5 | octopus octopus_deploy In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. | 0.9% | — |
| CVE-2022-20108 | MED 6.7 | google android In voice service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330702; Is | 0.1% | — |
| CVE-2022-20107 | MED 4.4 | google android In subtitle service, there is a possible application crash due to an integer overflow. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330673; Issue ID: DTV0333 | 0.1% | — |
| CVE-2022-20106 | MED 6.7 | google android In MM service, there is a possible out of bounds write due to a heap-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue | 0.1% | — |
| CVE-2022-20105 | MED 6.7 | google android In MM service, there is a possible out of bounds write due to a stack-based buffer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03330460; Issue | 0.1% | — |
| CVE-2022-1998 | HIGH 7.8 | fedoraproject fedora A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privil | 0.3% | — |
| CVE-2022-1992 | CRIT 9.1 | gogs gogs Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | 2.3% | — |
| CVE-2022-1976 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and po | 0.2% | — |
| CVE-2022-1975 | MED 5.5 | linux linux_kernel There is a sleep-in-atomic bug in /net/nfc/netlink.c that allows an attacker to crash the Linux kernel by simulating a nfc device from user-space. | 0.2% | — |
| CVE-2022-1974 | MED 4.1 | linux linux_kernel A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information. | 0.1% | — |
| CVE-2022-1973 | HIGH 7.1 | fedoraproject fedora A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem. | 0.3% | — |
| CVE-2022-1943 | HIGH 7.8 | linux linux_kernel A flaw out of bounds memory write in the Linux kernel UDF file system functionality was found in the way user triggers some file operation which triggers udf_write_fi(). A local user could use this flaw to crash the system or potentially | 0.3% | — |
| CVE-2022-1901 | MED 5.3 | octopus octopus_server In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | 0.5% | — |
| CVE-2022-1884 | CRIT 9.8 | gogs gogs A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upl | 1.8% | — |
| CVE-2022-1882 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the Linux kernel’s pipes functionality in how a user performs manipulations with the pipe post_one_notification() after free_pipe_info() that is already called. This flaw allows a local user to crash or potentially escalate t | 0.3% | — |
| CVE-2022-1852 | MED 5.5 | linux linux_kernel A NULL pointer dereference flaw was found in the Linux kernel’s KVM module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c. This flaw occurs while executing an illegal instruction in guest in the Intel CPU. | 0.3% | — |
| CVE-2022-1794 | MED 5.5 | codesys opc_da_server The CODESYS OPC DA Server prior V3.5.18.20 stores PLC passwords as plain text in its configuration file so that it is visible to all authorized Microsoft Windows users of the system. | 0.2% | — |
| CVE-2022-1789 | MED 6.8 | debian debian_linux With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference. | 0.3% | — |
| CVE-2022-1786 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges | 1.0% | — |
| CVE-2022-1734 | HIGH 7.0 | debian debian_linux A flaw in Linux Kernel found in nfcmrvl_nci_unregister_dev() in drivers/nfc/nfcmrvl/main.c can lead to use after free both read or write when non synchronized between cleanup routine and firmware download routine. | 0.5% | — |
| CVE-2022-1729 | HIGH 7.0 | linux linux_kernel A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc. | 0.3% | — |
| CVE-2022-1679 | HIGH 7.8 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privile | 0.8% | — |
| CVE-2022-1678 | MED 5.9 | linux linux_kernel An issue was discovered in the Linux Kernel from 4.18 to 4.19, an improper update of sock reference in TCP pacing can lead to memory/netns leak, which can be used by remote clients. | 2.9% | — |
| CVE-2022-1671 | HIGH 7.1 | linux linux_kernel A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information. | 0.3% | — |