56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.832 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-23013 | HIGH 8.8 | f5 big-ip_domain_name_system On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility | 0.8% | — |
| CVE-2022-22744 | HIGH 8.8 | mozilla firefox The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating s | 1.3% | — |
| CVE-2022-22493 | HIGH 8.8 | ibm websphere_automation_for_ibm_cloud_pak_for_watson_aiops IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449. | 0.3% | — |
| CVE-2022-22479 | HIGH 8.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0through 2.2.15.0 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 225887. | 0.3% | — |
| CVE-2022-22472 | HIGH 8.8 | ibm spectrum_protect_plus_container_backup_and_restore IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused | 0.9% | — |
| CVE-2022-22394 | HIGH 8.8 | ibm spectrum_protect The IBM Spectrum Protect 8.1.14.000 server could allow a remote attacker to bypass security restrictions, caused by improper enforcement of access controls. By signing in, an attacker could exploit this vulnerability to bypass security and gain unauthorized ad | 2.2% | — |
| CVE-2022-22182 | HIGH 8.8 | juniper junos A Cross-site Scripting (XSS) vulnerability in Juniper Networks Junos OS J-Web allows an attacker to construct a URL that when visited by another user enables the attacker to execute commands with the target's permissions, including an administrator. This issue | 0.7% | — |
| CVE-2022-22026 | HIGH 8.8 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-22019 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-22017 | HIGH 8.8 | microsoft remote_desktop_client Remote Desktop Client Remote Code Execution Vulnerability | 38.0% | — |
| CVE-2022-22014 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-22013 | HIGH 8.8 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-22005 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 16.8% | — |
| CVE-2022-21990 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 18.8% | — |
| CVE-2022-21984 | HIGH 8.8 | microsoft windows_10 Windows DNS Server Remote Code Execution Vulnerability | 4.8% | — |
| CVE-2022-21922 | HIGH 8.8 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21920 | HIGH 8.8 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-21857 | HIGH 8.8 | microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-21851 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21850 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21840 | HIGH 8.8 | microsoft excel Microsoft Office Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2022-2162 | HIGH 8.8 | fedoraproject fedora Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. | 1.2% | — |
| CVE-2022-20961 | HIGH 8.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vul | 0.4% | — |
| CVE-2022-20921 | HIGH 8.8 | cisco aci_multi-site_orchestrator A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker co | 1.2% | — |