56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.580 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-40189 | CRIT 9.8 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pig Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG f | 3.9% | — |
| CVE-2022-40145 | CRIT 9.8 | apache karaf This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext. | 2.4% | — |
| CVE-2022-40144 | CRIT 9.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations. | 2.3% | — |
| CVE-2022-39952 | CRIT 9.8 | fortinet fortinac A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute u | 99.8% | — |
| CVE-2022-39344 | CRIT 9.8 | microsoft azure_rtos_usbx Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memo | 2.0% | — |
| CVE-2022-39198 | CRIT 9.8 | apache dubbo A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior ve | 2.6% | — |
| CVE-2022-39135 | CRIT 9.8 | apache calcite Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefor | 2.0% | — |
| CVE-2022-38651 | CRIT 9.8 | vmware hyperic_server A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects pro | 0.8% | — |
| CVE-2022-38649 | CRIT 9.8 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG | 3.2% | — |
| CVE-2022-38221 | CRIT 9.8 | the_isle_evrima_project the_isle_evrima A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. | 1.8% | — |
| CVE-2022-38054 | CRIT 9.8 | apache airflow In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. | 1.9% | — |
| CVE-2022-37021 | CRIT 9.8 | apache geode Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgra | 2.4% | — |
| CVE-2022-36947 | CRIT 9.8 | faststone image_viewer Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow. | 2.8% | — |
| CVE-2022-36536 | CRIT 9.8 | syncovery syncovery An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens. | 4.0% | — |
| CVE-2022-35744 | CRIT 9.8 | microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-35741 | CRIT 9.8 | apache cloudstack Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be ena | 7.9% | — |
| CVE-2022-35280 | CRIT 9.8 | ibm robotic_process_automation_for_cloud_pak IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. | 0.8% | — |
| CVE-2022-34916 | CRIT 9.8 | apache flume Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JN | 2.8% | — |
| CVE-2022-34722 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34721 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 78.5% | — |
| CVE-2022-34718 | CRIT 9.8 | microsoft windows_10 Windows TCP/IP Remote Code Execution Vulnerability | 46.6% | — |
| CVE-2022-34715 | CRIT 9.8 | microsoft windows_server_2022 Windows Network File System Remote Code Execution Vulnerability | 80.4% | — |
| CVE-2022-33980 | CRIT 9.8 | apache commons_configuration Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configurat | 42.6% | — |
| CVE-2022-33874 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote atta | 2.9% | — |
| CVE-2022-33872 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote a | 2.9% | — |