IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-4326 MED 5.5 trellix endpoint_security Improper preservation of permissions vulnerability in Trellix Endpoint Agent (xAgent) prior to V35.31.22 on Windows allows a local user with administrator privileges to bypass the product protection to uninstall the agent via incorrectly applied permissions in 0.2%
CVE-2022-42722 MED 5.5 debian debian_linux In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices. 0.6%
CVE-2022-42721 MED 5.5 debian debian_linux A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code. 0.6%
CVE-2022-42703 MED 5.5 linux linux_kernel mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse. 0.9%
CVE-2022-4269 MED 5.5 linux linux_kernel A flaw was found in the Linux kernel Traffic Control (TC) subsystem. Using a specific networking configuration (redirecting egress packets to ingress using TC action "mirred") a local unprivileged user could trigger a CPU soft lockup (ABBA deadlock) when the t 0.2%
CVE-2022-42342 MED 5.5 adobe acrobat Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations s 0.5%
CVE-2022-42329 MED 5.5 debian debian_linux Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock 0.2%
CVE-2022-42328 MED 5.5 debian debian_linux Guests can trigger deadlock in Linux netback driver T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The patch for XSA-392 introduced another issue which might result in a deadlock 0.2%
CVE-2022-42266 MED 5.5 nvidia cloud_gaming NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can cause exposure of sensitive information to an actor that is not explicitly authorized to ha 0.2%
CVE-2022-41780 MED 5.5 f5 f5os-a In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. 0.5%
CVE-2022-4128 MED 5.5 linux linux_kernel A NULL pointer dereference issue was discovered in the Linux kernel in the MPTCP protocol when traversing the subflow list at disconnect time. A local user could use this flaw to potentially crash the system causing a denial of service. 0.2%
CVE-2022-4127 MED 5.5 linux linux_kernel A NULL pointer dereference issue was discovered in the Linux kernel in io_files_update_with_index_alloc. A local user could use this flaw to potentially crash the system causing a denial of service. 0.2%
CVE-2022-41218 MED 5.5 debian debian_linux In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release. 0.8%
CVE-2022-41205 MED 5.5 sap gui SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful exploitation, the attacker can gain access to registries which can cause a limited impact on confidentiality and high impact on availability of the application. 0.2%
CVE-2022-41105 MED 5.5 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 0.8%
CVE-2022-41104 MED 5.5 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 0.8%
CVE-2022-41103 MED 5.5 microsoft 365_apps Microsoft Word Information Disclosure Vulnerability 0.9%
CVE-2022-41098 MED 5.5 microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability 0.7%
CVE-2022-41074 MED 5.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0.5%
CVE-2022-41060 MED 5.5 microsoft 365_apps Microsoft Word Information Disclosure Vulnerability 0.8%
CVE-2022-41055 MED 5.5 microsoft windows_10 Windows Human Interface Device Information Disclosure Vulnerability 0.6%
CVE-2022-40954 MED 5.5 apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files 1.4%
CVE-2022-40768 MED 5.5 debian debian_linux drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. 0.3%
CVE-2022-40476 MED 5.5 linux linux_kernel A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service. 0.3%
CVE-2022-40140 MED 5.5 trendmicro apex_one An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to cause a denial-of-service on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged cod 0.4%