57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30992 | MED 6.1 | acronis cyber_protect Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | 0.5% | — |
| CVE-2022-30991 | MED 6.1 | acronis cyber_protect HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | 0.5% | — |
| CVE-2022-28732 | MED 6.1 | apache jspwiki A carefully crafted request on WeblogPlugin could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. Apache JSPWiki users should upgr | 82.0% | — |
| CVE-2022-28730 | MED 6.1 | apache jspwiki A carefully crafted request on AJAXPreview.jsp could trigger an XSS vulnerability on Apache JSPWiki, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. This vulnerability leverages | 85.4% | — |
| CVE-2022-28681 | MED 6.1 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2022-28186 | MED 6.1 | nvidia gpu_display_driver NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where the product receives input or data, but does not validate or incorrectly validates that the input has the properties that ar | 0.3% | — |
| CVE-2022-27509 | MED 6.1 | citrix application_delivery_controller_firmware Unauthenticated redirection to a malicious website | 0.5% | — |
| CVE-2022-27505 | MED 6.1 | citrix sd-wan_1000_firmware Reflected cross site scripting (XSS) | 0.5% | — |
| CVE-2022-27503 | MED 6.1 | citrix storefront_server Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 | 0.5% | — |
| CVE-2022-27166 | MED 6.1 | apache jspwiki A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. | 85.4% | — |
| CVE-2022-25256 | MED 6.1 | sas web_report_studio SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page t | 1.2% | — |
| CVE-2022-24969 | MED 6.1 | apache dubbo bypass CVE-2021-25640 > In Apache Dubbo prior to 2.6.12 and 2.7.15, the usage of parseURL method will lead to the bypass of the white host check which can cause open redirect or SSRF vulnerability. | 1.8% | — |
| CVE-2022-24948 | MED 6.1 | apache jspwiki A carefully crafted user preferences for submission could trigger an XSS vulnerability on Apache JSPWiki, related to the user preferences screen, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information ab | 2.3% | — |
| CVE-2022-24526 | MED 6.1 | microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability | 1.6% | — |
| CVE-2022-22477 | MED 6.1 | ibm websphere_application_server IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a | 0.6% | — |
| CVE-2022-22304 | MED 6.1 | fortinet fortiauthenticator_agent_for_microsoft_outlook_web_access An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2.1 may allow an unauthenticated attacker to perform an XSS attack via crafted HTTP GET requests. | 0.6% | — |
| CVE-2022-22242 | MED 6.1 | juniper junos A Cross-site Scripting (XSS) vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated attacker to run malicious scripts reflected off of J-Web to the victim's browser in the context of their session within J-Web. This issue a | 2.6% | — |
| CVE-2022-22217 | MED 6.1 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). The issue is caused by malformed MLD packet | 0.3% | — |
| CVE-2022-22048 | MED 6.1 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-21970 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-21954 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2022-21839 | MED 6.1 | microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability | 1.5% | — |
| CVE-2022-21813 | MED 6.1 | nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of serv | 0.2% | — |
| CVE-2022-20959 | MED 6.1 | cisco identity_services_engine A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This | 0.8% | — |
| CVE-2022-20944 | MED 6.1 | cisco ios_xe A vulnerability in the software image verification functionality of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches could allow an unauthenticated, physical attacker to execute unsigned code at system boot time. This vulnerability is due to an im | 0.2% | — |