57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41089 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41083 | HIGH 7.8 | microsoft jupyter Visual Studio Code Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-41077 | HIGH 7.8 | microsoft windows_10 Windows Fax Compose Form Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-41073 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 2.5% | |
| CVE-2022-41063 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41061 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-41057 | HIGH 7.8 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-41054 | HIGH 7.8 | microsoft windows_10 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-41052 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41051 | HIGH 7.8 | microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41050 | HIGH 7.8 | microsoft windows_10 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-41045 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-41034 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 67.5% | — |
| CVE-2022-41033 | HIGH 7.8 | microsoft windows_10_1507 Windows COM+ Event System Service Elevation of Privilege Vulnerability | 1.7% | |
| CVE-2022-41032 | HIGH 7.8 | fedoraproject fedora NuGet Client Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-41031 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-4095 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges. | 0.3% | — |
| CVE-2022-40710 | HIGH 7.8 | trendmicro deep_security_agent A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute | 0.2% | — |
| CVE-2022-40683 | HIGH 7.8 | fortinet fortiweb A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands | 0.2% | — |
| CVE-2022-40682 | HIGH 7.8 | fortinet forticlient A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to execute unauthorized code or commands via sending a crafted request to a specific named pipe. | 0.2% | — |
| CVE-2022-40679 | HIGH 7.8 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all versions, 6.2.0 through 6.2.4, 7.0.0 through 7.0.3, 7.1.0; FortiDDoS 4.x all versions, 5.0 all versions, 5.1 all | 0.2% | — |
| CVE-2022-40277 | HIGH 7.8 | joplinapp joplin Joplin version 2.8.8 allows an external attacker to execute arbitrary commands remotely on any client that opens a link in a malicious markdown file, via Joplin. This is possible because the application does not properly validate the schema/protocol of existin | 0.5% | — |
| CVE-2022-40274 | HIGH 7.8 | gridea gridea Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled. | 0.4% | — |
| CVE-2022-40142 | HIGH 7.8 | trendmicro apex_one A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileges on affected instal | 0.3% | — |
| CVE-2022-39959 | HIGH 7.8 | panini everest_engine Panini Everest Engine 2.0.4 allows unprivileged users to create a file named Everest.exe in the %PROGRAMDATA%\Panini folder. This leads to privilege escalation because a service, running as SYSTEM, uses the unquoted path of %PROGRAMDATA%\Panini\Everest Engine\ | 0.6% | — |