56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-49022 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac8021: fix possible oob access in ieee80211_get_rate_duration Fix possible out-of-bound access in ieee80211_get_rate_duration routine as reported by the following UBSAN report: UBSA | 0.3% | — |
| CVE-2022-48743 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: amd-xgbe: Fix skb data length underflow There will be BUG_ON() triggered in include/linux/skbuff.h leading to intermittent kernel panic, when the skb length underflow is detected. Fix | 0.6% | — |
| CVE-2022-48629 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct rng_alg expects that the destination buffer is completely filled if the function returns 0. | 0.5% | — |
| CVE-2022-47943 | HIGH 8.1 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case. | 3.5% | — |
| CVE-2022-47940 | HIGH 8.1 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.18 before 5.18.18. fs/ksmbd/smb2pdu.c lacks length validation in the non-padding case in smb2_write. | 1.4% | — |
| CVE-2022-45786 | HIGH 8.1 | apache age There are issues with the AGE drivers for Golang and Python that enable SQL injections to occur. This impacts AGE for PostgreSQL 11 & AGE for PostgreSQL 12, all versions up-to-and-including 1.1.0, when using those drivers. The fix is to update to the latest G | 0.9% | — |
| CVE-2022-44676 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-44670 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-42478 | HIGH 8.1 | fortinet fortisiem An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints. | 0.5% | — |
| CVE-2022-41674 | HIGH 8.1 | debian debian_linux An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c. | 3.9% | — |
| CVE-2022-41672 | HIGH 8.1 | apache airflow In Apache Airflow, prior to version 2.4.1, deactivating a user wouldn't prevent an already authenticated user from being able to continue using the UI or API. | 1.3% | — |
| CVE-2022-41157 | HIGH 8.1 | webcash serp_server_2.0 A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the SYSTEM authority. This vulnerability could allow attackers to leak or steal sensitive information or execute malicious commands. | 0.5% | — |
| CVE-2022-41088 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-41081 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-41044 | HIGH 8.1 | microsoft windows_7 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-41039 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-39327 | HIGH 8.1 | microsoft azure_command-line_interface Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have b | 3.5% | — |
| CVE-2022-38047 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-38023 | HIGH 8.1 | fedoraproject fedora Netlogon RPC Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-38000 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2022-37966 | HIGH 8.1 | fedoraproject fedora Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2022-37958 | HIGH 8.1 | microsoft windows_10 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability | 85.8% | — |
| CVE-2022-35846 | HIGH 8.1 | fortinet fortitester An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a | 0.8% | — |
| CVE-2022-35843 | HIGH 8.1 | fortinet fortios An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 th | 0.9% | — |
| CVE-2022-35830 | HIGH 8.1 | microsoft windows_server_2008 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 1.5% | — |