58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-27949 | HIGH 7.5 | apache airflow A vulnerability in UI of Apache Airflow allows an attacker to view unmasked secrets in rendered template values for tasks which were not executed (for example when they were depending on past and previous instances of the task failed). This issue affects Apach | 1.9% | — |
| CVE-2022-27944 | HIGH 7.5 | foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow an exportXFAData NULL pointer dereference. | 1.1% | — |
| CVE-2022-27674 | HIGH 7.5 | amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. | 0.7% | — |
| CVE-2022-27508 | HIGH 7.5 | citrix application_delivery_controller Unauthenticated denial of service | 1.0% | — |
| CVE-2022-27230 | HIGH 7.5 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x of F5 BIG-IP APM, and F5 BIG-IP Guided Configuration (GC) all versions prior to 9.0, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of F5 BIG-IP Guided Co | 0.5% | — |
| CVE-2022-27189 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when an Internet Content Adaptation Protocol (ICAP) profile is configu | 0.9% | — |
| CVE-2022-27008 | HIGH 7.5 | f5 njs nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array. | 1.7% | — |
| CVE-2022-26979 | HIGH 7.5 | foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. | 1.1% | — |
| CVE-2022-26931 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 2.6% | — |
| CVE-2022-26924 | HIGH 7.5 | microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability | 3.5% | — |
| CVE-2022-26915 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 3.6% | — |
| CVE-2022-26890 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when ASM or Advanced WAF, as well as APM, are configured on a virtual server, th | 0.9% | — |
| CVE-2022-26885 | HIGH 7.5 | apache dolphinscheduler When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher. | 1.3% | — |
| CVE-2022-26832 | HIGH 7.5 | microsoft .net_framework .NET Framework Denial of Service Vulnerability | 3.6% | — |
| CVE-2022-26831 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability | 3.3% | — |
| CVE-2022-26830 | HIGH 7.5 | microsoft windows_11 DiskUsage.exe Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-26779 | HIGH 7.5 | apache cloudstack Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that | 2.9% | — |
| CVE-2022-26650 | HIGH 7.5 | apache shenyu In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions | 2.6% | — |
| CVE-2022-26477 | HIGH 7.5 | apache systemds The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and wri | 2.2% | — |
| CVE-2022-26377 | HIGH 7.5 | apache http_server Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Ser | 21.1% | — |
| CVE-2022-26372 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when a DNS listener is configured on a virtual server with DNS queueing (default), undisclosed requests c | 0.9% | — |
| CVE-2022-25813 | HIGH 7.5 | apache ofbiz In Apache OFBiz, versions 18.12.05 and earlier, an attacker acting as an anonymous user of the ecommerce plugin, can insert a malicious content in a message “Subject” field from the "Contact us" page. Then a party manager needs to list the communications in th | 67.3% | — |
| CVE-2022-25763 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. | 2.0% | — |
| CVE-2022-25598 | HIGH 7.5 | apache dolphinscheduler Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher. | 2.0% | — |
| CVE-2022-25331 | HIGH 7.5 | trendmicro serverprotect Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process. | 3.1% | — |