57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-0187 | MED 6.1 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an out-of-bounds read can lead to denial of service. | 0.2% | — |
| CVE-2023-0186 | MED 6.1 | nvidia virtual_gpu NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer, where an out-of-bounds write can lead to denial of service and data tampering. | 0.2% | — |
| CVE-2022-48183 | MED 6.1 | lenovo thinkpad_t14s_gen_3_firmware A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | 0.3% | — |
| CVE-2022-48182 | MED 6.1 | lenovo thinkpad_t14s_gen_3_firmware A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | 0.3% | — |
| CVE-2022-47500 | MED 6.1 | apache helix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper des | 1.1% | — |
| CVE-2022-46907 | MED 6.1 | apache jspwiki A carefully crafted request on several JSPWiki plugins could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users | 1.2% | — |
| CVE-2022-45402 | MED 6.1 | apache airflow In Apache Airflow versions prior to 2.4.3, there was an open redirect in the webserver's `/login` endpoint. | 81.8% | — |
| CVE-2022-45051 | MED 6.1 | axiell iguana A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The module parameter on the Service.template.cls endpoint does not properly neutralise user input, resulting in the vulnerability. | 0.4% | — |
| CVE-2022-45049 | MED 6.1 | axiell iguana A reflected XSS vulnerability has been found in Axiell Iguana CMS, allowing an attacker to execute code in a victim's browser. The url parameter on the novelist.php endpoint does not properly neutralise user input, resulting in the vulnerability. | 0.4% | — |
| CVE-2022-43985 | MED 6.1 | apache airflow In Apache Airflow versions prior to 2.4.2, there was an open redirect in the webserver's `/confirm` endpoint. | 1.6% | — |
| CVE-2022-43982 | MED 6.1 | apache airflow In Apache Airflow versions prior to 2.4.2, the "Trigger DAG with config" screen was susceptible to XSS attacks via the `origin` query argument. | 1.5% | — |
| CVE-2022-42466 | MED 6.1 | apache isis Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this w | 1.3% | — |
| CVE-2022-40754 | MED 6.1 | apache airflow In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. | 1.6% | — |
| CVE-2022-40743 | MED 6.1 | apache traffic_server Improper Input Validation vulnerability for the xdebug plugin in Apache Software Foundation Apache Traffic Server can lead to cross site scripting and cache poisoning attacks.This issue affects Apache Traffic Server: 9.0.0 to 9.1.3. Users should upgrade to 9.1 | 1.1% | — |
| CVE-2022-39842 | MED 6.1 | debian debian_linux An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is | 0.6% | — |
| CVE-2022-38709 | MED 6.1 | ibm robotic_process_automation_for_cloud_pak IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 for Cloud Pak is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cred | 0.4% | — |
| CVE-2022-38376 | MED 6.1 | fortinet fortinac Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI before 9.4.1 allows an attacker to perform an XSS attack via crafted HTTP requests. | 0.6% | — |
| CVE-2022-35797 | MED 6.1 | microsoft windows_10 Windows Hello Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-35278 | MED 6.1 | apache artemis In Apache ActiveMQ Artemis prior to 2.24.0, an attacker could show malicious content and/or redirect users to a malicious URL in the web console by using HTML in the name of an address or queue. | 1.7% | — |
| CVE-2022-34330 | MED 6.1 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent | 0.4% | — |
| CVE-2022-34305 | MED 6.1 | apache tomcat In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability. | 6.6% | — |
| CVE-2022-31734 | MED 6.1 | cisco ws-c2940-8tf-s_firmware Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affecte | 0.6% | — |
| CVE-2022-31688 | MED 6.1 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window. | 0.4% | — |
| CVE-2022-31663 | MED 6.1 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in t | 0.7% | — |
| CVE-2022-31616 | MED 6.1 | nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where a local user with basic capabilities can cause an out-of-bounds read, which may lead to denial of service, or information di | 0.2% | — |