IT
58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.165 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-38011 HIGH 7.3 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.9%
CVE-2022-36263 HIGH 7.3 logitech streamlabs_desktop StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file. 0.4%
CVE-2022-36070 HIGH 7.3 python-poetry poetry Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute path. This can lead to th 0.4%
CVE-2022-35793 HIGH 7.3 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 9.1%
CVE-2022-35757 HIGH 7.3 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.8%
CVE-2022-35755 HIGH 7.3 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 9.8%
CVE-2022-33631 HIGH 7.3 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 0.8%
CVE-2022-32223 HIGH 7.3 nodejs node.js Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files 1.8%
CVE-2022-30170 HIGH 7.3 microsoft windows_10 Windows Credential Roaming Service Elevation of Privilege Vulnerability 1.6%
CVE-2022-28714 HIGH 7.3 f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, a 0.3%
CVE-2022-28339 HIGH 7.3 trendmicro housecall_for_home_networks Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges. 0.3%
CVE-2022-26921 HIGH 7.3 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 0.6%
CVE-2022-22248 HIGH 7.3 juniper junos_os_evolved An Incorrect Permission Assignment vulnerability in shell processing of Juniper Networks Junos OS Evolved allows a low-privileged local user to modify the contents of a configuration file which could cause another user to execute arbitrary commands within the 0.2%
CVE-2022-22189 HIGH 7.3 juniper contrail_service_orchestration An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently 0.2%
CVE-2022-22162 HIGH 7.3 juniper junos A Generation of Error Message Containing Sensitive Information vulnerability in the CLI of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to elevate these to the level of any other user logged in via J-Web at this time, p 0.2%
CVE-2022-22040 HIGH 7.3 microsoft windows_10 Internet Information Services Dynamic Compression Module Denial of Service Vulnerability 1.5%
CVE-2022-20739 HIGH 7.3 cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as the root user. The attacker must be authenticated on the affected system as a low-privi 0.6%
CVE-2022-0883 HIGH 7.3 snowsoftware snow_license_manager SLM has an issue with Windows Unquoted/Trusted Service Paths Security Issue. All installations version 9.x.x prior to 9.20.1 should be patched. 0.2%
CVE-2021-47441 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mlxsw: thermal: Fix out-of-bounds memory accesses Currently, mlxsw allows cooling states to be set above the maximum cooling state supported by the driver: # cat /sys/class/thermal/thermal 0.2%
CVE-2021-46912 HIGH 7.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: Make tcp_allowed_congestion_control readonly in non-init netns Currently, tcp_allowed_congestion_control is global and writable; writing to it in any net namespace will leak into all ot 0.2%
CVE-2021-44466 HIGH 7.3 leap bitmask_riseup_vpn Bitmask Riseup VPN 0.21.6 contains a local privilege escalation flaw due to improper access controls. When the software is installed with a non-default installation directory off of the system root, the installer fails to properly set ACLs. This allows lower p 0.4%
CVE-2021-44226 HIGH 7.3 razer synapse Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have pla 0.9%
CVE-2021-44206 HIGH 7.3 acronis cyber_protect_home_office Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 0.2%
CVE-2021-44205 HIGH 7.3 acronis cyber_protect_home_office Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 0.2%
CVE-2021-42955 HIGH 7.3 zohocorp manageengine_remote_access_plus Zoho Remote Access Plus Server Windows Desktop binary fixed in version 10.1.2132 is affected by an unauthorized password reset vulnerability. Because of the designed password reset mechanism, any non-admin Windows user can reset the password of the Remote Acce 0.4%