56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37401 | HIGH 8.8 | apache openoffice Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded res | 1.8% | — |
| CVE-2022-37400 | HIGH 8.8 | apache openoffice Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vecto | 0.9% | — |
| CVE-2022-37022 | HIGH 8.8 | apache geode Apache Geode versions up to 1.12.2 and 1.13.2 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 11. Any user wishing to protect against deserialization attacks involving JMX or RMI should upgrade to Apache Geode 1.15. U | 1.6% | — |
| CVE-2022-36564 | HIGH 8.8 | strawberryperl strawberryperl Incorrect access control in the install directory (C:\Strawberry) of StrawberryPerl v5.32.1.1 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | 1.2% | — |
| CVE-2022-36534 | HIGH 8.8 | syncovery syncovery Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. | 51.8% | — |
| CVE-2022-36364 | HIGH 8.8 | apache apache_calcite_avatica Apache Calcite Avatica JDBC driver creates HTTP client instances based on class names provided via `httpclient_impl` connection property; however, the driver does not verify if the class implements the expected interface before instantiating it, which can lead | 3.0% | — |
| CVE-2022-35841 | HIGH 8.8 | microsoft windows_10 Windows Enterprise App Management Service Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-35840 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-35836 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-35835 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-35834 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-35827 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2022-35826 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2022-35825 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-35823 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Remote Code Execution Vulnerability | 52.9% | — |
| CVE-2022-35805 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-35804 | HIGH 8.8 | microsoft windows_11 SMB Client and Server Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-35777 | HIGH 8.8 | microsoft visual_studio Visual Studio Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-35286 | HIGH 8.8 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814. | 0.3% | — |
| CVE-2022-35285 | HIGH 8.8 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230812. | 0.4% | — |
| CVE-2022-34734 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34733 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-34732 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34731 | HIGH 8.8 | microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-34730 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |