57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-36127 | HIGH 7.5 | apache skywalking_nodejs_agent A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection. | 1.8% | — |
| CVE-2022-36125 | HIGH 7.5 | apache avro It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addr | 1.5% | — |
| CVE-2022-36124 | HIGH 7.5 | apache avro It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apa | 1.4% | — |
| CVE-2022-35838 | HIGH 7.5 | microsoft windows_11 HTTP V3 Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-35833 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 3.0% | — |
| CVE-2022-35796 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2022-35769 | HIGH 7.5 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-35748 | HIGH 7.5 | microsoft windows_server_2012 HTTP.sys Denial of Service Vulnerability | 47.2% | — |
| CVE-2022-35742 | HIGH 7.5 | microsoft 365_apps Microsoft Outlook Denial of Service Vulnerability | 22.4% | — |
| CVE-2022-35724 | HIGH 7.5 | apache avro It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro versio | 1.7% | — |
| CVE-2022-35715 | HIGH 7.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231 | 1.0% | — |
| CVE-2022-35639 | HIGH 7.5 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. | 1.0% | — |
| CVE-2022-35272 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1 and 16.1.x before 16.1.3.1, when source-port preserve-strict is configured on an HTTP Message Routing Framework (MRF) virtual server, undisclosed traffic may cause the Traffic Management Microkernel (TMM) to produce a | 0.5% | — |
| CVE-2022-35245 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5.1, when a BIG-IP APM access policy is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Softwar | 0.7% | — |
| CVE-2022-35240 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when the Message Routing (MR) Message Queuing Telemetry Transport (MQTT) profile is configured on a virtual server, undisclosed requests can cause an increase in memor | 0.7% | — |
| CVE-2022-35236 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.2.2, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an HTTP2 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilization. Note: Software versions which have r | 0.7% | — |
| CVE-2022-34917 | HIGH 7.5 | apache kafka A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException | 1.3% | — |
| CVE-2022-34862 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when an LTM virtual server is configured to perform normalization, undisclosed requests can cause the Traffic Management Microkernel (TMM) to t | 1.3% | — |
| CVE-2022-34724 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Server Denial of Service Vulnerability | 3.7% | — |
| CVE-2022-34720 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 3.6% | — |
| CVE-2022-34701 | HIGH 7.5 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Denial of Service Vulnerability | 2.8% | — |
| CVE-2022-34689 | HIGH 7.5 | microsoft windows_10 Windows CryptoAPI Spoofing Vulnerability | 37.9% | — |
| CVE-2022-34655 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.6.1, and 14.1.x before 14.1.5, when an iRule containing the HTTP::payload command is configured on a virtual server, undisclosed traffic can cause Traffic Management Microkernel (TMM) to terminate. | 0.7% | — |
| CVE-2022-34651 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, when an LTM Client or Server SSL profile with TLS 1.3 enabled is configured on a virtual server, along with an iRule that calls HTTP::respond, undisclosed requests can cause the Traffic Mana | 0.7% | — |
| CVE-2022-34169 | HIGH 7.5 | apache xalan-java The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. Users are rec | 81.0% | — |