IT
57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.808 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-29144 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0%
CVE-2022-29143 HIGH 7.5 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-29117 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 5.0%
CVE-2022-29055 HIGH 7.5 fortinet fortios A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated atta 0.9%
CVE-2022-28716 HIGH 7.5 f5 big-ip_advanced_firewall_manager On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page o 0.8%
CVE-2022-28705 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual 0.9%
CVE-2022-28701 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are 0.9%
CVE-2022-28691 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when a Real Time Streaming Protocol (RTSP) profile is configured on a virtual server, undisclosed traffic c 0.9%
CVE-2022-28220 HIGH 7.5 apache james Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into 2.0%
CVE-2022-28129 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. 2.3%
CVE-2022-27949 HIGH 7.5 apache airflow A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apach 1.9%
CVE-2022-27944 HIGH 7.5 foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference. 1.1%
CVE-2022-27674 HIGH 7.5 amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. 0.7%
CVE-2022-27508 HIGH 7.5 citrix application_delivery_controller Unauthenticated denial of service 1.0%
CVE-2022-27230 HIGH 7.5 f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Co 0.5%
CVE-2022-27189 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configu 0.9%
CVE-2022-27008 HIGH 7.5 f5 njs nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array. 1.7%
CVE-2022-26979 HIGH 7.5 foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. 1.1%
CVE-2022-26931 HIGH 7.5 microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability 2.6%
CVE-2022-26924 HIGH 7.5 microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability 3.5%
CVE-2022-26915 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 3.6%
CVE-2022-26890 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual server, th 0.9%
CVE-2022-26885 HIGH 7.5 apache dolphinscheduler When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher. 1.3%
CVE-2022-26832 HIGH 7.5 microsoft .net_framework .NET Framework Denial of Service Vulnerability 3.6%
CVE-2022-26831 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability 3.3%