IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-27949 HIGH 7.5 apache airflow A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apach 1.9% —
CVE-2022-27944 HIGH 7.5 foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference. 1.1% —
CVE-2022-27674 HIGH 7.5 amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. 0.7% —
CVE-2022-27508 HIGH 7.5 citrix application_delivery_controller Unauthenticated denial of service 1.0% —
CVE-2022-27230 HIGH 7.5 f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Co 0.5% —
CVE-2022-27189 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configu 0.9% —
CVE-2022-27008 HIGH 7.5 f5 njs nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array. 1.7% —
CVE-2022-26979 HIGH 7.5 foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. 1.1% —
CVE-2022-26931 HIGH 7.5 microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability 2.6% —
CVE-2022-26924 HIGH 7.5 microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability 3.5% —
CVE-2022-26915 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 3.6% —
CVE-2022-26890 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual server, th 0.9% —
CVE-2022-26885 HIGH 7.5 apache dolphinscheduler When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher. 1.3% —
CVE-2022-26832 HIGH 7.5 microsoft .net_framework .NET Framework Denial of Service Vulnerability 3.6% —
CVE-2022-26831 HIGH 7.5 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability 3.3% —
CVE-2022-26830 HIGH 7.5 microsoft windows_11 DiskUsage.exe Remote Code Execution Vulnerability 1.7% —
CVE-2022-26779 HIGH 7.5 apache cloudstack Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that 2.9% —
CVE-2022-26650 HIGH 7.5 apache shenyu In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions 2.6% —
CVE-2022-26477 HIGH 7.5 apache systemds The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and wri 2.2% —
CVE-2022-26377 HIGH 7.5 apache http_server Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Ser 21.1% —
CVE-2022-26372 HIGH 7.5 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when a DNS listener is configured on a virtual server with DNS queueing (default), undisclosed requests c 0.9% —
CVE-2022-25813 HIGH 7.5 apache ofbiz In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in th 67.3% —
CVE-2022-25763 HIGH 7.5 apache traffic_server Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. 2.0% —
CVE-2022-25598 HIGH 7.5 apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. 2.0% —
CVE-2022-25331 HIGH 7.5 trendmicro serverprotect Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process. 3.1% —