58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-34690 | HIGH 7.1 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-34676 | HIGH 7.1 | nvidia cloud_gaming NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read may lead to denial of service, information disclosure, or data tampering. | 0.3% | — |
| CVE-2022-33742 | HIGH 7.1 | debian debian_linux Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with | 0.3% | — |
| CVE-2022-33741 | HIGH 7.1 | debian debian_linux Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with | 0.3% | — |
| CVE-2022-33740 | HIGH 7.1 | debian debian_linux Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with | 0.3% | — |
| CVE-2022-3202 | HIGH 7.1 | linux linux_kernel A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information. | 0.3% | — |
| CVE-2022-31613 | HIGH 7.1 | nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where any local user can cause a null-pointer dereference, which may lead to a kernel panic. | 0.2% | — |
| CVE-2022-31612 | HIGH 7.1 | nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to a system crash or a leak of internal | 0.2% | — |
| CVE-2022-30687 | HIGH 7.1 | trendmicro maximum_security_2022 Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files. | 0.4% | — |
| CVE-2022-30226 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-30225 | HIGH 7.1 | microsoft windows_10 Windows Media Player Network Sharing Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-26659 | HIGH 7.1 | docker docker_desktop Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, | 0.4% | — |
| CVE-2022-26365 | HIGH 7.1 | debian debian_linux Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with | 0.3% | — |
| CVE-2022-23805 | HIGH 7.1 | trendmicro worry-free_business_security A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server could allow a local attacker to send garbage data to a specific named pipe and crash the server. Please note: an attacker must first obtain th | 0.7% | — |
| CVE-2022-23511 | HIGH 7.1 | amazon cloudwatch_agent A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, | 0.5% | — |
| CVE-2022-23273 | HIGH 7.1 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 2.2% | — |
| CVE-2022-22977 | HIGH 7.1 | vmware tools VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to | 0.8% | — |
| CVE-2022-22753 | HIGH 7.1 | mozilla firefox A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other | 0.6% | — |
| CVE-2022-22022 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-21997 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-21827 | HIGH 7.1 | citrix gateway_plug-in An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt | 0.2% | — |
| CVE-2022-20956 | HIGH 7.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass authorization and access system files. This vulnerability is due to improper access control in the web-base | 1.4% | — |
| CVE-2022-20822 | HIGH 7.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read and delete files on an affected device. This vulnerability is due to insufficient validation of user-supplied in | 1.3% | — |
| CVE-2022-1973 | HIGH 7.1 | fedoraproject fedora A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem. | 0.3% | — |
| CVE-2022-1671 | HIGH 7.1 | linux linux_kernel A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information. | 0.3% | — |