IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.569 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-41073 HIGH 7.8 ransomware microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 2.4%
CVE-2020-3433 HIGH 7.8 ransomware cisco anyconnect_secure_mobility_client A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to hav 10.0%
CVE-2020-3153 MED 6.5 ransomware cisco anyconnect_secure_mobility_client A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the 27.5%
CVE-2022-41033 HIGH 7.8 microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability 1.7%
CVE-2022-40684 CRIT 9.8 ransomware fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an una 100.0%
CVE-2022-41082 HIGH 8.0 ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 100.0%
CVE-2022-41040 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 100.0%
CVE-2022-40139 HIGH 7.2 trendmicro apex_one Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, whi 2.8%
CVE-2013-6282 HIGH 8.8 linux linux_kernel The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted applica 39.7%
CVE-2013-2596 HIGH 7.8 linux linux_kernel Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel mem 3.3%
CVE-2013-2094 HIGH 8.4 linux linux_kernel The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call. 47.7%
CVE-2010-2568 HIGH 7.8 microsoft windows_7 Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 allows local users or remote attackers to execute arbitrary code via a crafted (1) .LNK or (2) .PIF shortcut file, which is not properly handle 91.3%
CVE-2022-37969 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 28.3%
CVE-2018-13374 MED 4.3 ransomware fortinet fortiadc A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a 38.1%
CVE-2022-24706 CRIT 9.8 apache couchdb In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including rec 92.4%
CVE-2022-24112 CRIT 9.8 apache apisix An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Ad 96.0%
CVE-2022-22963 CRIT 9.8 oracle banking_branch In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local r 99.9%
CVE-2022-0028 HIGH 8.6 paloaltonetworks pan-os A PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks. The DoS attack would appear to originate from a Palo Alto Networks PA-Series (hardware), VM-Series (vir 2.4%
CVE-2022-2856 MED 6.5 fedoraproject fedora Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. 4.5%
CVE-2022-26923 HIGH 8.8 microsoft windows_10_1507 Active Directory Domain Services Elevation of Privilege Vulnerability 83.0%
CVE-2022-21971 HIGH 7.8 microsoft windows_10_1809 Windows Runtime Remote Code Execution Vulnerability 53.9%
CVE-2017-15944 CRIT 9.8 paloaltonetworks pan-os Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7.1.x before 7.1.14, and 8.0.x before 8.0.6 allows remote attackers to execute arbitrary code via vectors involving the management interface. 98.3%
CVE-2022-34713 HIGH 7.8 microsoft windows_10_1507 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability 68.0%
CVE-2022-30333 HIGH 7.5 ransomware debian debian_linux RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. 99.1%
CVE-2022-22047 HIGH 7.8 microsoft windows_10_1507 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability 17.1%