IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-30145 HIGH 7.5 microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability 2.1% —
CVE-2022-30144 HIGH 7.5 microsoft windows_10 Windows Bluetooth Service Remote Code Execution Vulnerability 0.9% —
CVE-2022-30143 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 1.9% —
CVE-2022-30142 HIGH 7.5 microsoft windows_10 Windows File History Remote Code Execution Vulnerability 2.2% —
CVE-2022-30140 HIGH 7.5 microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability 1.9% —
CVE-2022-30139 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.2% —
CVE-2022-29885 HIGH 7.5 apache tomcat The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the 73.5% —
CVE-2022-29804 HIGH 7.5 golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. 2.1% —
CVE-2022-29491 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (c 0.9% —
CVE-2022-29404 HIGH 7.5 apache http_server In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. 6.2% —
CVE-2022-29369 HIGH 7.5 f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. 1.2% —
CVE-2022-29266 HIGH 7.5 apache apisix In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information. 8.1% —
CVE-2022-29265 HIGH 7.5 apache nifi Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The followi 2.6% —
CVE-2022-29158 HIGH 7.5 apache ofbiz Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 2.0% —
CVE-2022-29145 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 5.1% —
CVE-2022-29144 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0% —
CVE-2022-29143 HIGH 7.5 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.9% —
CVE-2022-29117 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 5.0% —
CVE-2022-29055 HIGH 7.5 fortinet fortios A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated atta 1.0% —
CVE-2022-28716 HIGH 7.5 f5 big-ip_advanced_firewall_manager On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page o 0.8% —
CVE-2022-28705 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual 0.9% —
CVE-2022-28701 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, when the stream profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are 0.9% —
CVE-2022-28691 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when a Real Time Streaming Protocol (RTSP) profile is configured on a virtual server, undisclosed traffic c 0.9% —
CVE-2022-28220 HIGH 7.5 apache james Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. Fix of CVE-2021-38542, which solved similar problem fron Apache James 3.6.1, is subject to a parser differential and do not take into 2.0% —
CVE-2022-28129 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. 2.3% —