IT
56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.831 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-34727 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.3%
CVE-2022-34726 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 2.3%
CVE-2022-34717 HIGH 8.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.9%
CVE-2022-34700 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability 3.2%
CVE-2022-34691 HIGH 8.8 microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability 2.1%
CVE-2022-34669 HIGH 8.8 nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can access or modify system files or other files that are critical to the application, which may lead to code execution, denial of service 0.3%
CVE-2022-34271 HIGH 8.8 apache atlas A vulnerability in import module of Apache Atlas allows an authenticated user to write to web server filesystem. This issue affects Apache Atlas versions from 0.8.4 to 2.2.0. 1.4%
CVE-2022-34158 HIGH 8.8 apache jspwiki A carefully crafted invocation on the Image plugin could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow a group privilege escalation of the attacker's account. Further examination of this issue established that it could also b 1.2%
CVE-2022-3405 HIGH 8.8 acronis cyber_backup Code execution and sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 29486, Acronis Cyber Backup 12.5 (Windows, Linux) before buil 5.3%
CVE-2022-33891 HIGH 8.8 apache spark The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabled, a code path in Ht 93.1%
CVE-2022-33869 HIGH 8.8 fortinet fortiwan An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to e 1.3%
CVE-2022-33140 HIGH 8.8 apache nifi The optional ShellUserGroupProvider in Apache NiFi 1.10.0 to 1.16.2 and Apache NiFi Registry 0.6.0 to 1.16.2 does not neutralize arguments for group resolution commands, allowing injection of operating system commands on Linux and macOS platforms. The ShellUse 3.6%
CVE-2022-31739 HIGH 8.8 mozilla firefox When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Oth 0.7%
CVE-2022-31696 HIGH 8.8 vmware cloud_foundation VMware ESXi contains a memory corruption vulnerability that exists in the way it handles a network socket. A malicious actor with local access to ESXi may exploit this issue to corrupt memory leading to an escape of the ESXi sandbox. 0.3%
CVE-2022-31673 HIGH 8.8 vmware vrealize_operations VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can create and leak hex dumps, leading to information disclosure. Successful exploitation can lead to a remote code execution. 1.6%
CVE-2022-30670 HIGH 8.8 adobe robohelp_server RoboHelp Server earlier versions than RHS 11 Update 3 are affected by an Improper Authorization vulnerability which could lead to privilege escalation. An authenticated attacker could leverage this vulnerability to achieve full administrator privileges. Exploi 1.4%
CVE-2022-30608 HIGH 8.8 ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295. 0.3%
CVE-2022-30303 HIGH 8.8 fortinet fortiweb An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through 6.3.19, 6.4 all versions may allow an authenticated attacker to execute arbitrary shell code as `root` user vi 2.5%
CVE-2022-30221 HIGH 8.8 microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability 2.0%
CVE-2022-30216 HIGH 8.8 microsoft windows_10 Windows Server Service Tampering Vulnerability 88.6%
CVE-2022-30165 HIGH 8.8 microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability 4.3%
CVE-2022-30161 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.4%
CVE-2022-30158 HIGH 8.8 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 3.3%
CVE-2022-30157 HIGH 8.8 microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability 7.5%
CVE-2022-30153 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.4%