IT
58.135 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.135 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-26071 HIGH 7.4 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a flaw in the way reply ICMP packets are limited in the Traffic Manage 1.1%
CVE-2022-22190 HIGH 7.4 juniper paragon_active_assurance_control_center An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated attacker to leverage a crafted URL to generate PDF reports, potentially containing sensitive configuration information. A feature 1.0%
CVE-2022-22176 HIGH 7.4 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker sending a malformed DHCP packet to cause a crash of jdhcpd and thereby a Denial 0.4%
CVE-2022-22163 HIGH 7.4 juniper junos An Improper Input Validation vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). If a device is configured as DHCPv6 local 0.4%
CVE-2022-20945 HIGH 7.4 cisco catalyst_9800-40_firmware A vulnerability in the 802.11 association frame validation of Cisco Catalyst 9100 Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insu 0.4%
CVE-2022-20915 HIGH 7.4 cisco ios_xe A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW) of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability 0.3%
CVE-2022-20866 HIGH 7.4 cisco adaptive_security_appliance_software A vulnerability in the handling of RSA keys on devices running Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve an RSA private key. This vulnerability 17.4%
CVE-2022-20860 HIGH 7.4 cisco nexus_dashboard A vulnerability in the SSL/TLS implementation of Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to alter communications with associated controllers or view sensitive information. This vulnerability exists because SSL server certificates 0.5%
CVE-2022-20853 HIGH 7.4 cisco telepresence_video_communication_server A vulnerability in the REST API of Cisco Expressway Series and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insuffi 0.6%
CVE-2022-20817 HIGH 7.4 cisco ata_187_analog_telephone_adapter_firmware A vulnerability in Cisco Unified IP Phones could allow an unauthenticated, remote attacker to impersonate another user's phone if the Cisco Unified Communications Manager (CUCM) is in secure mode. This vulnerability is due to improper key generation during the 1.2%
CVE-2022-20814 HIGH 7.4 cisco telepresence_video_communication_server A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.  The vulnerability is due to a lack of validation 0.9%
CVE-2022-20769 HIGH 7.4 cisco wireless_lan_controller_software A vulnerability in the authentication functionality of Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insuff 0.5%
CVE-2022-20761 HIGH 7.4 cisco ios A vulnerability in the integrated wireless access point (AP) packet processing of the Cisco 1000 Series Connected Grid Router (CGR1K) could allow an unauthenticated, adjacent attacker to cause a denial of service condition on an affected device. This vulnerabi 0.4%
CVE-2022-20742 HIGH 7.4 cisco adaptive_security_appliance_software A vulnerability in an IPsec VPN library of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to read or modify data within an IPsec IKEv2 VPN tunnel. This vulnerab 0.5%
CVE-2022-20684 HIGH 7.4 cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause an affected device to unexpec 0.5%
CVE-2022-0016 HIGH 7.4 paloaltonetworks globalprotect An improper handling of exceptional conditions vulnerability exists within the Connect Before Logon feature of the Palo Alto Networks GlobalProtect app that enables a local attacker to escalate to SYSTEM or root privileges when authenticating with Connect Befo 0.2%
CVE-2021-47464 HIGH 7.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: audit: fix possible null-pointer dereference in audit_filter_rules Fix possible null-pointer dereference in audit_filter_rules. audit_filter_rules() error: we previously assumed 'ctx' coul 0.2%
CVE-2021-44549 HIGH 7.4 apache sling_commons_messaging_mail Apache Sling Commons Messaging Mail provides a simple layer on top of JavaMail/Jakarta Mail for OSGi to send mails via SMTPS. To reduce the risk of "man in the middle" attacks additional server identity checks must be performed when accessing mail servers. For 1.9%
CVE-2021-43892 HIGH 7.4 microsoft biztalk_esb_toolkit Microsoft BizTalk ESB Toolkit Spoofing Vulnerability 2.9%
CVE-2021-43219 HIGH 7.4 microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability 3.7%
CVE-2021-40457 HIGH 7.4 microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability 1.6%
CVE-2021-38665 HIGH 7.4 microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability 7.0%
CVE-2021-37980 HIGH 7.4 debian debian_linux Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows. 1.5%
CVE-2021-36183 HIGH 7.4 fortinet forticlient An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for Forticlient updates. 0.3%
CVE-2021-3618 HIGH 7.4 debian debian_linux ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker having access to victim's traffic at the 2.0%