IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.831 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-41047 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.5%
CVE-2022-41040 HIGH 8.8 ransomware microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 100.0%
CVE-2022-41038 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 2.8%
CVE-2022-41037 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 1.7%
CVE-2022-41036 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 1.7%
CVE-2022-40955 HIGH 8.8 apache inlong In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leadin 2.3%
CVE-2022-40127 HIGH 8.8 apache airflow A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0. 85.7%
CVE-2022-39947 HIGH 8.8 fortinet fortiadc A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiADC version 6.2.0 through 6.2.3, FortiADC version version 6.1.0 through 6.1.6, FortiADC version 6.0.0 through 6. 2.9%
CVE-2022-39944 HIGH 8.8 apache linkis In Apache Linkis <=1.2.0 when used with the MySQL Connector/J, a deserialization vulnerability with possible remote code execution impact exists when an attacker has write access to a database and configures a JDBC EC with a MySQL data source and malicious par 1.9%
CVE-2022-38374 HIGH 8.8 fortinet fortiadc A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and even 1.7%
CVE-2022-38369 HIGH 8.8 apache iotdb Apache IoTDB version 0.13.0 is vulnerable by session id attack. Users should upgrade to version 0.13.1 which addresses this issue. 1.1%
CVE-2022-38362 HIGH 8.8 apache apache-airflow-providers-docker Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. 1.8%
CVE-2022-38053 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 76.4%
CVE-2022-38045 HIGH 8.8 microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability 2.2%
CVE-2022-38040 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.6%
CVE-2022-38034 HIGH 8.8 microsoft windows_10 Windows Workstation Service Elevation of Privilege Vulnerability 3.0%
CVE-2022-38031 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2022-38016 HIGH 8.8 microsoft windows_10 Windows Local Security Authority (LSA) Elevation of Privilege Vulnerability 0.5%
CVE-2022-38009 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1.7%
CVE-2022-38008 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 1.7%
CVE-2022-37982 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.6%
CVE-2022-37976 HIGH 8.8 microsoft windows_server_2008 Active Directory Certificate Services Elevation of Privilege Vulnerability 2.0%
CVE-2022-37975 HIGH 8.8 microsoft windows_10 Windows Group Policy Elevation of Privilege Vulnerability 1.5%
CVE-2022-37961 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 50.0%
CVE-2022-37435 HIGH 8.8 apache shenyu Apache ShenYu Admin has insecure permissions, which may allow low-privilege administrators to modify high-privilege administrator's passwords. This issue affects Apache ShenYu 2.4.2 and 2.4.3. 1.3%