57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30190 | HIGH 7.8 | ransomware microsoft windows_10_1507 A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The | 99.2% | |
| CVE-2022-30188 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-30180 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Information Disclosure Vulnerability | 2.2% | — |
| CVE-2022-30179 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-30178 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30177 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30176 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-30175 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-30174 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 3.2% | — |
| CVE-2022-30173 | HIGH 7.8 | microsoft excel Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-30168 | HIGH 7.8 | microsoft photos Microsoft Photos App Remote Code Execution Vulnerability | 2.6% | — |
| CVE-2022-30167 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30166 | HIGH 7.8 | microsoft windows_10 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2022-30164 | HIGH 7.8 | microsoft windows_10 Kerberos AppContainer Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2022-30160 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 6.3% | — |
| CVE-2022-30147 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2022-30138 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-30135 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-30132 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-30131 | HIGH 7.8 | microsoft windows_server_2016 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-29968 | HIGH 7.8 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. | 1.1% | — |
| CVE-2022-2978 | HIGH 7.8 | debian debian_linux A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate | 0.2% | — |
| CVE-2022-2977 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possi | 0.2% | — |
| CVE-2022-2964 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. | 0.3% | — |
| CVE-2022-29594 | HIGH 7.8 | eginnovations eg_agent eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. | 0.3% | — |