56.831 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.831 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30129 | HIGH 8.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 41.3% | — |
| CVE-2022-29376 | HIGH 8.8 | apachefriends xampp Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | 1.3% | — |
| CVE-2022-29141 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29139 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-29137 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-29133 | HIGH 8.8 | microsoft windows_11 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-29131 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29129 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29128 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.7% | — |
| CVE-2022-29108 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 11.9% | — |
| CVE-2022-28944 | HIGH 8.8 | emcosoftware msi_package_builder Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7. | 1.5% | — |
| CVE-2022-27487 | HIGH 8.8 | fortinet fortideceptor A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version 4.1.0, 4.0.0 through 4.0.2 and before 3.3.3 allows a remote authenticated attacker to perform unauthorized API | 1.0% | — |
| CVE-2022-27223 | HIGH 8.8 | debian debian_linux In drivers/usb/gadget/udc/udc-xilinx.c in the Linux kernel before 5.16.12, the endpoint index is not validated and might be manipulated by the host for out-of-array access. | 2.2% | — |
| CVE-2022-26927 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 4.4% | — |
| CVE-2022-26923 | HIGH 8.8 | microsoft windows_10_1507 Active Directory Domain Services Elevation of Privilege Vulnerability | 83.5% | |
| CVE-2022-26183 | HIGH 8.8 | pnpm pnpm PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is | 1.6% | — |
| CVE-2022-26117 | HIGH 8.8 | fortinet fortinac An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, 8.7.6 and below, 8.8.11 and below, 9.1.5 and below, 9.2.3 and below may allow an authenticated attacker to acce | 0.9% | — |
| CVE-2022-24971 | HIGH 8.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 2.7% | — |
| CVE-2022-24947 | HIGH 8.8 | apache jspwiki Apache JSPWiki user preferences form is vulnerable to CSRF attacks, which can lead to account takeover. Apache JSPWiki users should upgrade to 2.11.2 or later. | 1.2% | — |
| CVE-2022-24541 | HIGH 8.8 | microsoft windows_10 Windows Server Service Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2022-24528 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-24508 | HIGH 8.8 | microsoft windows_10 Win32 File Enumeration Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-24500 | HIGH 8.8 | microsoft windows_10 Windows SMB Remote Code Execution Vulnerability | 38.0% | — |
| CVE-2022-24492 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 3.0% | — |
| CVE-2022-24487 | HIGH 8.8 | microsoft windows_10 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | 2.1% | — |