56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-48199 | HIGH 8.8 | softperfect networx SoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privileged user account that abuses the Notifications function. The Notifications function allows for arbitrary binary execution | 0.7% | — |
| CVE-2022-47942 | HIGH 8.8 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is a heap-based buffer overflow in set_ntacl_dacl, related to use of SMB2_QUERY_INFO_HE after a malformed SMB2_SET_INFO_HE command. | 3.6% | — |
| CVE-2022-46763 | HIGH 8.8 | trueconf server A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code. | 1.0% | — |
| CVE-2022-45412 | HIGH 8.8 | mozilla firefox When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems | 0.8% | — |
| CVE-2022-45052 | HIGH 8.8 | axiell iguana A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server. | 0.7% | — |
| CVE-2022-44693 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-44690 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 82.1% | — |
| CVE-2022-44645 | HIGH 8.8 | apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures new datasource with a MySQL data source and maliciou | 1.9% | — |
| CVE-2022-44635 | HIGH 8.8 | apache fineract Apache Fineract allowed an authenticated user to perform remote code execution due to a path traversal vulnerability in a file upload component of Apache Fineract, allowing an attacker to run remote code. This issue affects Apache Fineract version 1.8.0 and pr | 68.8% | — |
| CVE-2022-4439 | HIGH 8.8 | google chrome Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: | 0.6% | — |
| CVE-2022-43955 | HIGH 8.8 | fortinet fortiweb An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow an unauthenticated and remote a | 0.6% | — |
| CVE-2022-43719 | HIGH 8.8 | apache superset Two legacy REST API endpoints for approval and request access are vulnerable to cross site request forgery. This issue affects Apache Superset version 1.5.2 and prior versions and version 2.0.0. | 0.6% | — |
| CVE-2022-43396 | HIGH 8.8 | apache kylin In the fix for CVE-2022-24697, a blacklist is used to filter user input commands. But there is a risk of being bypassed. The user can control the command by controlling the kylin.engine.spark-cmd parameter of conf. | 55.3% | — |
| CVE-2022-42735 | HIGH 8.8 | apache shenyu Improper Privilege Management vulnerability in Apache Software Foundation Apache ShenYu. ShenYu Admin allows low-privilege low-level administrators create users with higher privileges than their own. This issue affects Apache ShenYu: 2.5.0. Upgrade to Apac | 1.2% | — |
| CVE-2022-42719 | HIGH 8.8 | debian debian_linux A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code. | 1.3% | — |
| CVE-2022-41678 | HIGH 8.8 | apache activemq Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution. In details, in ActiveMQ configurations, jetty allows org.jolokia.http.AgentServlet to handler request to /api/jolokia org.jolokia.http.HttpRequestHandler#handlePo | 85.8% | — |
| CVE-2022-41622 | HIGH 8.8 | f5 big-ip_access_policy_manager In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 92.3% | — |
| CVE-2022-41335 | HIGH 8.8 | fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy version 7.2.0 through 7.2.1, 7.0.0 through 7.0.7 and before 2.0.10, FortiSwitchManager 7.2.0 and before 7.0.0 a | 0.9% | — |
| CVE-2022-41334 | HIGH 8.8 | fortinet fortios An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow a remote, unauthenticated attacker to launch a cross site scripting (XSS) attack via the "redir" parameter of | 0.7% | — |
| CVE-2022-41330 | HIGH 8.8 | fortinet fortios An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9, version 6.4.0 through 6.4.11 and before 6.2.12 and FortiProxy version 7 | 0.6% | — |
| CVE-2022-41128 | HIGH 8.8 | microsoft windows_10_1507 Windows Scripting Languages Remote Code Execution Vulnerability | 24.6% | |
| CVE-2022-41106 | HIGH 8.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-41080 | HIGH 8.8 | ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 77.3% | |
| CVE-2022-41062 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-41048 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.5% | — |