58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22966 | HIGH 7.2 | vmware vcloud_director An authenticated, high privileged malicious actor with network access to the VMware Cloud Director tenant or provider may be able to exploit a remote code execution vulnerability to gain access to the server. | 6.6% | — |
| CVE-2022-22958 | HIGH 7.2 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malici | 3.1% | — |
| CVE-2022-22957 | HIGH 7.2 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two remote code execution vulnerabilities (CVE-2022-22957 & CVE-2022-22958). A malicious actor with administrative access can trigger deserialization of untrusted data through malici | 23.9% | — |
| CVE-2022-22375 | HIGH 7.2 | ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. | 1.2% | — |
| CVE-2022-22186 | HIGH 7.2 | juniper junos Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress interface, instead of being discarded. S | 0.6% | — |
| CVE-2022-22167 | HIGH 7.2 | juniper junos A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on | 0.7% | — |
| CVE-2022-22157 | HIGH 7.2 | juniper junos A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on | 0.7% | — |
| CVE-2022-21957 | HIGH 7.2 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-0024 | HIGH 7.2 | paloaltonetworks pan-os A vulnerability exists in Palo Alto Networks PAN-OS software that enables an authenticated network-based PAN-OS administrator to upload a specifically created configuration that disrupts system processes and potentially execute arbitrary code with root privile | 1.5% | — |
| CVE-2021-43889 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-42294 | HIGH 7.2 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-40469 | HIGH 7.2 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 7.6% | — |
| CVE-2021-38927 | HIGH 7.2 | ibm aspera_console IBM Aspera Console 3.4.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. I | 0.3% | — |
| CVE-2021-32585 | HIGH 7.2 | fortinet fortiwan An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. | 0.7% | — |
| CVE-2021-31966 | HIGH 7.2 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2021-31384 | HIGH 7.2 | juniper junos Due to a Missing Authorization weakness and Insufficient Granularity of Access Control in a specific device configuration, a vulnerability exists in Juniper Networks Junos OS on SRX Series whereby an attacker who attempts to access J-Web administrative interfa | 1.2% | — |
| CVE-2021-31375 | HIGH 7.2 | juniper junos An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may ca | 0.8% | — |
| CVE-2021-31200 | HIGH 7.2 | microsoft neural_network_intelligence Common Utilities Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-31196 | HIGH 7.2 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 54.1% | |
| CVE-2021-3054 | HIGH 7.2 | paloaltonetworks pan-os A time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permission to upload plugins to execute arbitrary code with root user privileges. This issue impacts | 0.9% | — |
| CVE-2021-26610 | HIGH 7.2 | nhn-commerce godomall5 The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code. | 0.5% | — |
| CVE-2021-26422 | HIGH 7.2 | microsoft lync_server Skype for Business and Lync Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2021-25251 | HIGH 7.2 | trendmicro antivirus\+_security_2020 The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator | 2.6% | — |
| CVE-2021-24015 | HIGH 7.2 | fortinet fortimail An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specifically crafted HTTP requests. | 1.2% | — |
| CVE-2021-24009 | HIGH 7.2 | fortinet fortiwan Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically craf | 1.5% | — |