56.960 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.960 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24504 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-24490 | HIGH 8.1 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 3.1% | — |
| CVE-2022-24469 | HIGH 8.1 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-23272 | HIGH 8.1 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 2.5% | — |
| CVE-2022-23270 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 70.3% | — |
| CVE-2022-23256 | HIGH 8.1 | microsoft azure_data_explorer Azure Data Explorer Spoofing Vulnerability | 1.6% | — |
| CVE-2022-22241 | HIGH 8.1 | juniper junos An Improper Input Validation vulnerability in the J-Web component of Juniper Networks Junos OS may allow an unauthenticated attacker to access data without proper authorization. Utilizing a crafted POST request, deserialization may occur which could lead to un | 1.2% | — |
| CVE-2022-22038 | HIGH 8.1 | microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-22035 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-22029 | HIGH 8.1 | microsoft windows_server_2008 Windows Network File System Remote Code Execution Vulnerability | 5.2% | — |
| CVE-2022-21991 | HIGH 8.1 | microsoft visual_studio_code Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2022-21972 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 79.8% | — |
| CVE-2022-20968 | HIGH 8.1 | cisco ip_phone_7811_firmware A vulnerability in the Cisco Discovery Protocol processing feature of Cisco IP Phone 7800 and 8800 Series firmware could allow an unauthenticated, adjacent attacker to cause a stack overflow on an affected device. This vulnerability is due to insufficient i | 6.1% | — |
| CVE-2022-0030 | HIGH 8.1 | paloaltonetworks pan-os An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privilege | 0.9% | — |
| CVE-2021-47620 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: refactor malicious adv data check Check for out-of-bound read was being performed at the end of while num_reports loop, and would fill journal with false positives. Added check to | 0.3% | — |
| CVE-2021-47611 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mac80211: validate extended element ID is present Before attempting to parse an extended element, verify that the extended element ID is present. | 0.3% | — |
| CVE-2021-47433 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix abort logic in btrfs_replace_file_extents Error injection testing uncovered a case where we'd end up with a corrupt file system with a missing extent in the middle of a file. Thi | 0.6% | — |
| CVE-2021-47160 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: dsa: mt7530: fix VLAN traffic leaks PCR_MATRIX field was set to all 1's when VLAN filtering is enabled, but was not reset when it is disabled, which may cause traffic leaks: ip link a | 0.3% | — |
| CVE-2021-47131 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix use-after-free after the TLS device goes down and up When a netdev with active TLS offload goes down, tls_device_down is called to stop the offload and tear down the TLS context | 0.7% | — |
| CVE-2021-44759 | HIGH 8.1 | apache traffic_server Improper Authentication vulnerability in TLS origin validation of Apache Traffic Server allows an attacker to create a man in the middle attack. This issue affects Apache Traffic Server 8.0.0 to 8.1.0. | 1.6% | — |
| CVE-2021-43217 | HIGH 8.1 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 6.4% | — |
| CVE-2021-42753 | HIGH 8.1 | fortinet fortiweb An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an | 1.1% | — |
| CVE-2021-42638 | HIGH 8.1 | printerlogic web_stack PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution. | 5.5% | — |
| CVE-2021-42635 | HIGH 8.1 | printerlogic web_stack PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution. | 5.6% | — |
| CVE-2021-42631 | HIGH 8.1 | printerlogic virtual_appliance PrinterLogic Web Stack versions 19.1.1.13 SP9 and below deserializes attacker controlled leading to pre-auth remote code execution. | 6.2% | — |