56.743 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.743 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26629 | CRIT 9.1 | splus soroushplus An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function. | 3.2% | — |
| CVE-2022-25312 | CRIT 9.1 | apache any23 An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacke | 2.9% | — |
| CVE-2022-23944 | CRIT 9.1 | apache shenyu User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 79.0% | — |
| CVE-2022-23441 | CRIT 9.1 | fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors. | 0.9% | — |
| CVE-2022-22952 | CRIT 9.1 | vmware carbon_black_app_control VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains a file upload vulnerability. A malicious actor with administrative access to the VMware App Control administration interface m | 1.5% | — |
| CVE-2022-22951 | CRIT 9.1 | vmware carbon_black_app_control VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network access to the VMware App | 20.3% | — |
| CVE-2022-22721 | CRIT 9.1 | apache http_server If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier. | 41.9% | — |
| CVE-2022-22489 | CRIT 9.1 | ibm mq IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM | 1.6% | — |
| CVE-2022-20829 | CRIT 9.1 | cisco adaptive_security_device_manager A vulnerability in the packaging of Cisco Adaptive Security Device Manager (ASDM) images and the validation of those images by Cisco Adaptive Security Appliance (ASA) Software could allow an authenticated, remote attacker with administrative privileges to uplo | 3.4% | — |
| CVE-2022-1992 | CRIT 9.1 | gogs gogs Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. | 2.3% | — |
| CVE-2022-0742 | CRIT 9.1 | linux linux_kernel Memory leak in icmp6 implementation in Linux Kernel 5.13+ allows a remote attacker to DoS a host by making it go out-of-memory via icmp6 packets of type 130 or 131. We recommend upgrading past commit 2d3916f3189172d5c69d33065c3c21119fe539fc. | 5.0% | — |
| CVE-2021-47478 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry le | 0.7% | — |
| CVE-2021-47348 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes of the actual target field, the code was reading 8. This could result in a corrupted value if the | 1.0% | — |
| CVE-2021-44521 | CRIT 9.1 | apache cassandra When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. | 55.0% | — |
| CVE-2021-44140 | CRIT 9.1 | apache jspwiki Remote attackers may delete arbitrary files in a system hosting a JSPWiki instance, versions up to 2.11.0.M8, by using a carefuly crafted http request on logout, given that those files are reachable to the user running the JSPWiki instance. Apache JSPWiki user | 6.2% | — |
| CVE-2021-40525 | CRIT 9.1 | apache james Apache James ManagedSieve implementation alongside with the file storage for sieve scripts is vulnerable to path traversal, allowing reading and writing any file. This vulnerability had been patched in Apache James 3.6.1 and higher. We recommend the upgrade. D | 3.7% | — |
| CVE-2021-39233 | CRIT 9.1 | apache ozone In Apache Ozone versions prior to 1.2.0, Container related Datanode requests of Ozone Datanode were not properly authorized and can be called by any client. | 2.3% | — |
| CVE-2021-39231 | CRIT 9.1 | apache ozone In Apache Ozone versions prior to 1.2.0, Various internal server-to-server RPC endpoints are available for connections, making it possible for an attacker to download raw data from Datanode and Ozone manager and modify Ratis replication configuration. | 2.3% | — |
| CVE-2021-39063 | CRIT 9.1 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: | 0.7% | — |
| CVE-2021-38948 | CRIT 9.1 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 2114 | 2.0% | — |
| CVE-2021-38555 | CRIT 9.1 | apache any23 An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to int | 2.8% | — |
| CVE-2021-34473 | CRIT 9.1 | ransomware microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 100.0% | |
| CVE-2021-3033 | CRIT 9.1 | paloaltonetworks prisma_cloud An improper verification of cryptographic signature vulnerability exists in the Palo Alto Networks Prisma Cloud Compute console. This vulnerability enables an attacker to bypass signature validation during SAML authentication by logging in to the Prisma Cloud | 1.2% | — |
| CVE-2021-29943 | CRIT 9.1 | apache solr When using ConfigurableInternodeAuthHadoopPlugin for authentication, Apache Solr versions prior to 8.8.2 would forward/proxy distributed requests using server credentials instead of original client credentials. This would result in incorrect authorization reso | 5.4% | — |
| CVE-2021-27078 | CRIT 9.1 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 20.0% | — |