IT
57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.808 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30556 HIGH 7.5 apache http_server Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. 5.3%
CVE-2022-30522 HIGH 7.5 apache http_server If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. 89.5%
CVE-2022-30333 HIGH 7.5 ransomware debian debian_linux RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. 99.1%
CVE-2022-30215 HIGH 7.5 microsoft windows_server_2016 Active Directory Federation Services Elevation of Privilege Vulnerability 1.8%
CVE-2022-30211 HIGH 7.5 microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability 2.0%
CVE-2022-30194 HIGH 7.5 microsoft windows_10 Windows WebBrowser Control Remote Code Execution Vulnerability 1.5%
CVE-2022-30152 HIGH 7.5 microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.8%
CVE-2022-30150 HIGH 7.5 microsoft windows_10 Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability 3.4%
CVE-2022-30149 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.9%
CVE-2022-30146 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.9%
CVE-2022-30145 HIGH 7.5 microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability 2.1%
CVE-2022-30144 HIGH 7.5 microsoft windows_10 Windows Bluetooth Service Remote Code Execution Vulnerability 0.9%
CVE-2022-30143 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.9%
CVE-2022-30142 HIGH 7.5 microsoft windows_10 Windows File History Remote Code Execution Vulnerability 2.2%
CVE-2022-30140 HIGH 7.5 microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability 1.9%
CVE-2022-30139 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.2%
CVE-2022-29885 HIGH 7.5 apache tomcat The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the 73.5%
CVE-2022-29804 HIGH 7.5 golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. 2.1%
CVE-2022-29491 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (c 0.9%
CVE-2022-29404 HIGH 7.5 apache http_server In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. 6.4%
CVE-2022-29369 HIGH 7.5 f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. 1.2%
CVE-2022-29266 HIGH 7.5 apache apisix In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information. 8.1%
CVE-2022-29265 HIGH 7.5 apache nifi Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The followi 2.6%
CVE-2022-29158 HIGH 7.5 apache ofbiz Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 2.0%
CVE-2022-29145 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 5.1%