58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-40146 | HIGH 7.5 | apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. | 7.4% | — |
| CVE-2022-40141 | HIGH 7.5 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server. | 0.9% | — |
| CVE-2022-40082 | HIGH 7.5 | cloudwego hertz Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. | 0.9% | — |
| CVE-2022-39337 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke | 1.1% | — |
| CVE-2022-38370 | HIGH 7.5 | apache iotdb Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. | 1.3% | — |
| CVE-2022-38166 | HIGH 7.5 | f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. | 0.7% | — |
| CVE-2022-38046 | HIGH 7.5 | microsoft windows_10 Web Account Manager Information Disclosure Vulnerability | 1.9% | — |
| CVE-2022-38041 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 2.2% | — |
| CVE-2022-38036 | HIGH 7.5 | microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability | 2.2% | — |
| CVE-2022-38013 | HIGH 7.5 | fedoraproject fedora .NET Core and Visual Studio Denial of Service Vulnerability | 4.0% | — |
| CVE-2022-37978 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass | 1.5% | — |
| CVE-2022-37972 | HIGH 7.5 | microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability | 1.9% | — |
| CVE-2022-37866 | HIGH 7.5 | apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" | 1.7% | — |
| CVE-2022-36946 | HIGH 7.5 | debian debian_linux nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a neg | 7.6% | — |
| CVE-2022-36374 | HIGH 7.5 | intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2022-36127 | HIGH 7.5 | apache skywalking_nodejs_agent A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection. | 1.8% | — |
| CVE-2022-36125 | HIGH 7.5 | apache avro It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addr | 1.5% | — |
| CVE-2022-36124 | HIGH 7.5 | apache avro It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apa | 1.4% | — |
| CVE-2022-35838 | HIGH 7.5 | microsoft windows_11 HTTP V3 Denial of Service Vulnerability | 2.7% | — |
| CVE-2022-35833 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 3.0% | — |
| CVE-2022-35796 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2022-35769 | HIGH 7.5 | microsoft windows_10 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-35748 | HIGH 7.5 | microsoft windows_server_2012 HTTP.sys Denial of Service Vulnerability | 47.2% | — |
| CVE-2022-35742 | HIGH 7.5 | microsoft 365_apps Microsoft Outlook Denial of Service Vulnerability | 22.4% | — |
| CVE-2022-35724 | HIGH 7.5 | apache avro It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro versio | 1.7% | — |