56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-34727 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34726 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34717 | HIGH 8.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-34700 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2022-34691 | HIGH 8.8 | microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2022-34669 | HIGH 8.8 | nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service | 0.3% | — |
| CVE-2022-34271 | HIGH 8.8 | apache atlas A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. | 1.4% | — |
| CVE-2022-34158 | HIGH 8.8 | apache jspwiki A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also b | 1.2% | — |
| CVE-2022-3405 | HIGH 8.8 | acronis cyber_backup Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before buil | 5.3% | — |
| CVE-2022-33891 | HIGH 8.8 | apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht | 93.1% | |
| CVE-2022-33869 | HIGH 8.8 | fortinet fortiwan An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to e | 1.3% | — |
| CVE-2022-33140 | HIGH 8.8 | apache nifi The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUse | 3.6% | — |
| CVE-2022-31739 | HIGH 8.8 | mozilla firefox When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Oth | 0.7% | — |
| CVE-2022-31696 | HIGH 8.8 | vmware cloud_foundation VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. | 0.3% | — |
| CVE-2022-31673 | HIGH 8.8 | vmware vrealize_operations VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution. | 1.6% | — |
| CVE-2022-30670 | HIGH 8.8 | adobe robohelp_server RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploi | 1.4% | — |
| CVE-2022-30608 | HIGH 8.8 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295. | 0.3% | — |
| CVE-2022-30303 | HIGH 8.8 | fortinet fortiweb An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user vi | 2.5% | — |
| CVE-2022-30221 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-30216 | HIGH 8.8 | microsoft windows_10 Windows Server Service Tampering Vulnerability | 88.6% | — |
| CVE-2022-30165 | HIGH 8.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 4.3% | — |
| CVE-2022-30161 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-30158 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 3.3% | — |
| CVE-2022-30157 | HIGH 8.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 7.5% | — |
| CVE-2022-30153 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.4% | — |