57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-23291 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23290 | HIGH 7.8 | microsoft windows_10 Windows Inking COM Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23282 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-23276 | HIGH 7.8 | microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-23266 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-23222 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. | 1.9% | — |
| CVE-2022-23205 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 2.3% | — |
| CVE-2022-23200 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.1.1 (and earlier) and 18.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 3.0% | — |
| CVE-2022-23188 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. | 4.4% | — |
| CVE-2022-23187 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interacti | 4.5% | — |
| CVE-2022-23186 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.3% | — |
| CVE-2022-23120 | HIGH 7.8 | trendmicro deep_security_agent A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first | 6.4% | — |
| CVE-2022-22973 | HIGH 7.8 | vmware cloud_foundation VMware Workspace ONE Access and Identity Manager contain a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | 2.4% | — |
| CVE-2022-22964 | HIGH 7.8 | vmware horizon VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation that allows a user to escalate to root due to a vulnerable configuration file. | 0.2% | — |
| CVE-2022-22962 | HIGH 7.8 | vmware horizon VMware Horizon Agent for Linux (prior to 22.x) contains a local privilege escalation as a user is able to change the default shared folder location due to a vulnerable symbolic link. Successful exploitation can result in linking to a root owned file. | 0.3% | — |
| CVE-2022-22960 | HIGH 7.8 | vmware cloud_foundation VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due to improper permissions in support scripts. A malicious actor with local access can escalate privileges to 'root'. | 35.8% | |
| CVE-2022-22945 | HIGH 7.8 | vmware cloud_foundation VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root. | 0.4% | — |
| CVE-2022-22942 | HIGH 7.8 | vmware photon_os The vmwgfx driver contains a local privilege escalation vulnerability that allows unprivileged users to gain access to files opened by other processes on the system through a dangling 'file' pointer. | 2.6% | — |
| CVE-2022-22718 | HIGH 7.8 | microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability | 18.5% | |
| CVE-2022-22715 | HIGH 7.8 | microsoft windows_10 Named Pipe File System Elevation of Privilege Vulnerability | 12.6% | — |
| CVE-2022-22709 | HIGH 7.8 | microsoft vp9_video_extensions VP9 Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-22528 | HIGH 7.8 | sap adaptive_server_enterprise SAP Adaptive Server Enterprise (ASE) - version 16.0, installation makes an entry in the system PATH environment variable in Windows platform which, under certain conditions, allows a Standard User to execute malicious Windows binaries which may lead to privile | 0.3% | — |
| CVE-2022-22516 | HIGH 7.8 | codesys control_rte_sl The SysDrv3S driver in the CODESYS Control runtime system on Microsoft Windows allows any system user to read and write within restricted memory space. | 0.3% | — |
| CVE-2022-22454 | HIGH 7.8 | ibm infosphere_information_server_on_cloud IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | 0.3% | — |
| CVE-2022-22301 | HIGH 7.8 | fortinet fortiap-c An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI commands with specific | 0.3% | — |