IT
57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.808 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-41333 HIGH 7.5 fortinet fortirecorder_firmware An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests. 7.2%
CVE-2022-41118 HIGH 7.5 microsoft windows_10 Windows Scripting Languages Remote Code Execution Vulnerability 1.1%
CVE-2022-41085 HIGH 7.5 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0.7%
CVE-2022-41058 HIGH 7.5 microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.1%
CVE-2022-41056 HIGH 7.5 microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability 2.1%
CVE-2022-41053 HIGH 7.5 microsoft windows_10 Windows Kerberos Denial of Service Vulnerability 2.1%
CVE-2022-40705 HIGH 7.5 apache soap An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versio 1.6%
CVE-2022-40676 HIGH 7.5 fortinet fortinac A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 all 0.5%
CVE-2022-40604 HIGH 7.5 apache airflow In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction. 1.7%
CVE-2022-40308 HIGH 7.5 apache archiva If anonymous read enabled, it's possible to read the database file directly without logging in. 1.2%
CVE-2022-40146 HIGH 7.5 apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. 6.3%
CVE-2022-40141 HIGH 7.5 trendmicro apex_one A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server. 1.2%
CVE-2022-40082 HIGH 7.5 cloudwego hertz Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. 0.9%
CVE-2022-39337 HIGH 7.5 apache hertzbeat Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke 1.1%
CVE-2022-38370 HIGH 7.5 apache iotdb Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. 1.3%
CVE-2022-38166 HIGH 7.5 f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. 0.7%
CVE-2022-38046 HIGH 7.5 microsoft windows_10 Web Account Manager Information Disclosure Vulnerability 1.8%
CVE-2022-38041 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 2.1%
CVE-2022-38036 HIGH 7.5 microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability 2.2%
CVE-2022-38013 HIGH 7.5 fedoraproject fedora .NET Core and Visual Studio Denial of Service Vulnerability 4.0%
CVE-2022-37978 HIGH 7.5 microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass 1.5%
CVE-2022-37972 HIGH 7.5 microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability 1.6%
CVE-2022-37866 HIGH 7.5 apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" 1.7%
CVE-2022-36946 HIGH 7.5 debian debian_linux nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a neg 7.2%
CVE-2022-36374 HIGH 7.5 intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access. 0.2%