IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-44673 HIGH 7.0 microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability 5.2%
CVE-2022-44669 HIGH 7.0 microsoft windows_10 Windows Error Reporting Elevation of Privilege Vulnerability 0.3%
CVE-2022-42267 HIGH 7.0 nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering. 0.1%
CVE-2022-41745 HIGH 7.0 trendmicro apex_one An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted message to cause memory corruption on a certain service process which could lead to local privilege escalation on affected installations. P 0.7%
CVE-2022-41744 HIGH 7.0 trendmicro apex_one A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component could allow a local attacker to escalate privileges and turn a specific working directory into a mount point on affected installations. Please n 0.2%
CVE-2022-41743 HIGH 7.0 f5 nginx_ingress_controller NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_hls_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its crash or potential other impact using a specially crafted audio or video file 0.2%
CVE-2022-41741 HIGH 7.0 debian debian_linux NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to co 0.8%
CVE-2022-4149 HIGH 7.0 netskope netskope The Netskope client service (prior to R96) on Windows runs as NT AUTHORITY\SYSTEM which writes log files to a writable directory (C:\Users\Public\netSkope) for a standard user. The files are created and written with a SYSTEM account except one file (logplaceho 0.2%
CVE-2022-41222 HIGH 7.0 canonical ubuntu_linux mm/mremap.c in the Linux kernel before 5.13.3 has a use-after-free via a stale TLB because an rmap lock is not held during a PUD move. 0.5%
CVE-2022-41114 HIGH 7.0 microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2022-38029 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.6%
CVE-2022-38027 HIGH 7.0 microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability 0.4%
CVE-2022-38021 HIGH 7.0 microsoft windows_10 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability 0.4%
CVE-2022-38014 HIGH 7.0 microsoft azure_iot_edge_for_linux Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability 0.3%
CVE-2022-34725 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 5.4%
CVE-2022-33877 HIGH 7.0 fortinet forticlient An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated att 0.2%
CVE-2022-33646 HIGH 7.0 microsoft azure_batch Azure Batch Node Agent Elevation of Privilege Vulnerability 0.4%
CVE-2022-33644 HIGH 7.0 microsoft windows_10 Xbox Live Save Service Elevation of Privilege Vulnerability 0.4%
CVE-2022-30298 HIGH 7.0 fortinet fortisoar An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root. 0.2%
CVE-2022-3028 HIGH 7.0 debian debian_linux A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak 0.2%
CVE-2022-30224 HIGH 7.0 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 0.5%
CVE-2022-30202 HIGH 7.0 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 4.5%
CVE-2022-30151 HIGH 7.0 microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 0.5%
CVE-2022-2961 HIGH 7.0 fedoraproject fedora A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th 0.3%
CVE-2022-2959 HIGH 7.0 linux linux_kernel A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. T 0.4%