IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.580 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-33127 CRIT 9.8 diffy_project diffy The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string. 1.7%
CVE-2022-32533 CRIT 9.8 apache jetspeed Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dor 3.9%
CVE-2022-32532 CRIT 9.8 apache shiro Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. 25.6%
CVE-2022-3229 CRIT 9.8 unifiedremote unified_remote Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this no 66.4%
CVE-2022-31813 CRIT 9.8 apache http_server Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application. 3.3%
CVE-2022-31767 CRIT 9.8 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 227980. 5.0%
CVE-2022-31706 CRIT 9.8 vmware vrealize_log_insight The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution. 87.1%
CVE-2022-31704 CRIT 9.8 vmware vrealize_log_insight The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution. 81.0%
CVE-2022-31702 CRIT 9.8 vmware vrealize_network_insight vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. 1.6%
CVE-2022-31692 CRIT 9.8 netapp active_iq_unified_manager Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or include dispatcher types. Specifically, an application is vulnerable when all of the following are true: The application expec 3.4%
CVE-2022-31691 CRIT 9.8 vmware bosh_editor Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library for YAML editing supp 2.5%
CVE-2022-31689 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. 0.8%
CVE-2022-31687 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. 0.8%
CVE-2022-31686 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. 1.0%
CVE-2022-31685 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. 1.0%
CVE-2022-31657 CRIT 9.8 vmware access_connector VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain. 1.3%
CVE-2022-31656 CRIT 9.8 vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to a 22.9%
CVE-2022-30136 CRIT 9.8 microsoft windows_server_2012 Windows Network File System Remote Code Execution Vulnerability 74.7%
CVE-2022-30133 CRIT 9.8 microsoft windows_10 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability 2.7%
CVE-2022-30055 CRIT 9.8 mersenne prime95 Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. 3.9%
CVE-2022-29599 CRIT 9.8 apache maven_shared_utils In Apache Maven maven-shared-utils prior to version 3.3.3, the Commandline class can emit double-quoted strings without proper escaping, allowing shell injection attacks. 4.4%
CVE-2022-29379 CRIT 9.8 f5 njs Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not p 1.8%
CVE-2022-29130 CRIT 9.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 3.8%
CVE-2022-29063 CRIT 9.8 apache ofbiz The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or 3.9%
CVE-2022-28890 CRIT 9.8 apache jena A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena version 4.4.0 and prior versions. Apache Jena 4.2.x and 4.3.x do not allow external entities. 2.5%