57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21843 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 3.4% | — |
| CVE-2022-21546 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix WRITE_SAME No Data Buffer crash In newer version of the SBC specs, we have a NDOB bit that indicates there is no data buffer that gets written out. If this bit is set using | 0.4% | — |
| CVE-2022-21155 | HIGH 7.5 | fernhillsoftware scada_server A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. | 1.1% | — |
| CVE-2022-20960 | HIGH 7.5 | cisco email_security_appliance A vulnerability in Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain T | 0.8% | — |
| CVE-2022-20918 | HIGH 7.5 | cisco firepower_services_software_for_asa A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Preventi | 0.9% | — |
| CVE-2022-20854 | HIGH 7.5 | cisco secure_firewall_management_center A vulnerability in the processing of SSH connections of Cisco Firepower Management Center (FMC) and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device | 0.9% | — |
| CVE-2022-20785 | HIGH 7.5 | cisco secure_endpoint On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0. | 7.0% | — |
| CVE-2022-20783 | HIGH 7.5 | cisco roomos A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This | 1.4% | — |
| CVE-2022-20773 | HIGH 7.5 | cisco umbrella_virtual_appliance A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance (VA) could allow an unauthenticated, remote attacker to impersonate a VA. This vulnerability is due to the presence of a static SSH host key. An attacker could ex | 1.2% | — |
| CVE-2022-20771 | HIGH 7.5 | cisco secure_endpoint On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in the TIFF file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS versio | 5.8% | — |
| CVE-2022-2075 | HIGH 7.5 | octopus octopus_server In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build information request validation. | 0.7% | — |
| CVE-2022-2074 | HIGH 7.5 | octopus octopus_server In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Template. | 0.8% | — |
| CVE-2022-20696 | HIGH 7.5 | cisco catalyst_sd-wan_manager A vulnerability in the binding configuration of Cisco SD-WAN vManage Software containers could allow an unauthenticated, adjacent attacker who has access to the VPN0 logical network to also access the messaging service ports on an affected system. This vulnera | 0.4% | — |
| CVE-2022-20685 | HIGH 7.5 | cisco cyber_vision A vulnerability in the Modbus preprocessor of the Snort detection engine could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer overflow while processing Modb | 1.4% | — |
| CVE-2022-20653 | HIGH 7.5 | cisco asyncos A vulnerability in the DNS-based Authentication of Named Entities (DANE) email verification component of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) conditio | 1.8% | — |
| CVE-2022-2049 | HIGH 7.5 | octopus octopus_server In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload function. | 0.7% | — |
| CVE-2022-2013 | HIGH 7.5 | octopus octopus_deploy In Octopus Server after version 2022.1.1495 and before 2022.1.2647 if private spaces were enabled via the experimental feature flag all new users would have access to the Script Console within their private space. | 0.9% | — |
| CVE-2022-1199 | HIGH 7.5 | linux linux_kernel A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability. | 2.0% | — |
| CVE-2022-0400 | HIGH 7.5 | linux linux_kernel An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos. | 1.7% | — |
| CVE-2022-0280 | HIGH 7.5 | microsoft windows A race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted | 0.3% | — |
| CVE-2021-47559 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: Fix NULL pointer dereferencing in smc_vlan_by_tcpsk() Coverity reports a possible NULL dereferencing problem: in smc_vlan_by_tcpsk(): 6. returned_null: netdev_lower_get_next return | 0.5% | — |
| CVE-2021-47515 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: seg6: fix the iif in the IPv6 socket control block When an IPv4 packet is received, the ip_rcv_core(...) sets the receiving interface index into the IPv4 socket control block (v5.16-rc4, net | 0.7% | — |
| CVE-2021-47486 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: riscv, bpf: Fix potential NULL dereference The bpf_jit_binary_free() function requires a non-NULL argument. When the RISC-V BPF JIT fails to converge in NR_JIT_ITERATIONS steps, jit_data->he | 0.7% | — |
| CVE-2021-47448 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix possible stall on recvmsg() recvmsg() can enter an infinite loop if the caller provides the MSG_WAITALL, the data present in the receive queue is not sufficient to fulfill the req | 0.5% | — |
| CVE-2021-47397 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb We should always check if skb_header_pointer's return is NULL before using it, otherwise it may cause null-ptr-deref, as s | 0.8% | — |