IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.831 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-37401 HIGH 8.8 apache openoffice Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded res 1.8%
CVE-2022-37400 HIGH 8.8 apache openoffice Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vecto 0.9%
CVE-2022-37022 HIGH 8.8 apache geode Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. U 1.6%
CVE-2022-36564 HIGH 8.8 strawberryperl strawberryperl Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. 1.2%
CVE-2022-36534 HIGH 8.8 syncovery syncovery Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. 51.8%
CVE-2022-36364 HIGH 8.8 apache apache_calcite_avatica Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead 3.0%
CVE-2022-35841 HIGH 8.8 microsoft windows_10 Windows Enterprise App Management Service Remote Code Execution Vulnerability 2.8%
CVE-2022-35840 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-35836 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-35835 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-35834 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-35827 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.1%
CVE-2022-35826 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.1%
CVE-2022-35825 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.2%
CVE-2022-35823 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability 52.9%
CVE-2022-35805 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability 2.5%
CVE-2022-35804 HIGH 8.8 microsoft windows_11 SMB Client and Server Remote Code Execution Vulnerability 2.8%
CVE-2022-35777 HIGH 8.8 microsoft visual_studio Visual Studio Remote Code Execution Vulnerability 2.0%
CVE-2022-35286 HIGH 8.8 ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814. 0.3%
CVE-2022-35285 HIGH 8.8 ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812. 0.4%
CVE-2022-34734 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.3%
CVE-2022-34733 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-34732 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.3%
CVE-2022-34731 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 1.9%
CVE-2022-34730 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.3%