58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-32230 | HIGH 7.5 | microsoft windows_10 Microsoft Windows SMBv3 suffers from a null pointer dereference in versions of Windows prior to the April, 2022 patch set. By sending a malformed FileNormalizedNameInformation SMBv3 request over a named pipe, an attacker can cause a Blue Screen of Death (BSOD) | 7.5% | — |
| CVE-2022-31781 | HIGH 7.5 | apache tapestry Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause catastrophic backtracking, taking exponential time to complete. Specifically, this | 1.9% | — |
| CVE-2022-31780 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 frame handling of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.3% | — |
| CVE-2022-31779 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 header parsing of Apache Traffic Server allows an attacker to smuggle requests. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.4% | — |
| CVE-2022-31778 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in handling the Transfer-Encoding header of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 8.0.0 to 9.0.2. | 2.0% | — |
| CVE-2022-31710 | HIGH 7.5 | vmware vrealize_log_insight vRealize Log Insight contains a deserialization vulnerability. An unauthenticated malicious actor can remotely trigger the deserialization of untrusted data which could result in a denial of service. | 1.5% | — |
| CVE-2022-31703 | HIGH 7.5 | vmware vrealize_log_insight The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. | 1.8% | — |
| CVE-2022-31675 | HIGH 7.5 | vmware vrealize_operations VMware vRealize Operations contains an authentication bypass vulnerability. An unauthenticated malicious actor with network access may be able to create a user with administrative privileges. | 0.8% | — |
| CVE-2022-31662 | HIGH 7.5 | vmware access_connector VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability. A malicious actor with network access may be able to access arbitrary files. | 1.2% | — |
| CVE-2022-30995 | HIGH 7.5 | acronis cyber_backup Sensitive information disclosure due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before build 16545. | 3.3% | — |
| CVE-2022-30994 | HIGH 7.5 | acronis cyber_protect Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240 | 0.6% | — |
| CVE-2022-30993 | HIGH 7.5 | acronis cyber_protect Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | 0.6% | — |
| CVE-2022-30990 | HIGH 7.5 | acronis agent Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037 | 0.9% | — |
| CVE-2022-30634 | HIGH 7.5 | golang go Infinite loop in Read in crypto/rand before Go 1.17.11 and Go 1.18.3 on Windows allows attacker to cause an indefinite hang by passing a buffer larger than 1 << 32 - 1 bytes. | 2.2% | — |
| CVE-2022-30557 | HIGH 7.5 | foxit pdf_editor Foxit PDF Reader and PDF Editor before 11.2.2 have a Type Confusion issue that causes a crash because of Unsigned32 mishandling during JavaScript execution. | 4.4% | — |
| CVE-2022-30556 | HIGH 7.5 | apache http_server Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer. | 5.1% | — |
| CVE-2022-30522 | HIGH 7.5 | apache http_server If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort. | 89.5% | — |
| CVE-2022-30333 | HIGH 7.5 | ransomware debian debian_linux RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. | 99.1% | |
| CVE-2022-30215 | HIGH 7.5 | microsoft windows_server_2016 Active Directory Federation Services Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2022-30211 | HIGH 7.5 | microsoft windows_10 Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-30194 | HIGH 7.5 | microsoft windows_10 Windows WebBrowser Control Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-30152 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.8% | — |
| CVE-2022-30150 | HIGH 7.5 | microsoft windows_10 Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability | 3.4% | — |
| CVE-2022-30149 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-30146 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.9% | — |