56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-41073 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 2.4% | |
| CVE-2020-3433 | HIGH 7.8 | ransomware cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to hav | 10.0% | |
| CVE-2020-3153 | MED 6.5 | ransomware cisco anyconnect_secure_mobility_client A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the | 27.5% | |
| CVE-2022-41033 | HIGH 7.8 | microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2022-40684 | CRIT 9.8 | ransomware fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an una | 100.0% | |
| CVE-2022-41082 | HIGH 8.0 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2022-41040 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 100.0% | |
| CVE-2022-40139 | HIGH 7.2 | trendmicro apex_one Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, whi | 2.8% | |
| CVE-2013-6282 | HIGH 8.8 | linux linux_kernel The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted applica | 39.7% | |
| CVE-2013-2596 | HIGH 7.8 | linux linux_kernel Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel mem | 3.3% | |
| CVE-2013-2094 | HIGH 8.4 | linux linux_kernel The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call. | 47.7% | |
| CVE-2010-2568 | HIGH 7.8 | microsoft windows_7 Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handle | 91.3% | |
| CVE-2022-37969 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 28.3% | |
| CVE-2018-13374 | MED 4.3 | ransomware fortinet fortiadc A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a | 38.1% | |
| CVE-2022-24706 | CRIT 9.8 | apache couchdb In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including rec | 92.4% | |
| CVE-2022-24112 | CRIT 9.8 | apache apisix An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Ad | 96.0% | |
| CVE-2022-22963 | CRIT 9.8 | oracle banking_branch In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local r | 99.9% | |
| CVE-2022-0028 | HIGH 8.6 | paloaltonetworks pan-os A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (vir | 2.4% | |
| CVE-2022-2856 | MED 6.5 | fedoraproject fedora Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. | 4.5% | |
| CVE-2022-26923 | HIGH 8.8 | microsoft windows_10_1507 Active Directory Domain Services Elevation of Privilege Vulnerability | 83.0% | |
| CVE-2022-21971 | HIGH 7.8 | microsoft windows_10_1809 Windows Runtime Remote Code Execution Vulnerability | 53.9% | |
| CVE-2017-15944 | CRIT 9.8 | paloaltonetworks pan-os Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. | 98.3% | |
| CVE-2022-34713 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | 68.0% | |
| CVE-2022-30333 | HIGH 7.5 | ransomware debian debian_linux RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. | 99.1% | |
| CVE-2022-22047 | HIGH 7.8 | microsoft windows_10_1507 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 17.1% |