IT
56.580 CVE tracked
773 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.580 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-28331 CRIT 9.8 apache portable_runtime On Windows, Apache Portable Runtime 1.7.0 and earlier may write beyond the end of a stack based buffer in apr_socket_sendv(). This is a result of integer overflow. 1.6%
CVE-2022-28054 CRIT 9.8 vandyke vshell Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. 31.2%
CVE-2022-2778 CRIT 9.8 octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. 0.7%
CVE-2022-27518 CRIT 9.8 citrix application_delivery_controller_firmware Unauthenticated remote arbitrary code execution 6.9%
CVE-2022-27510 CRIT 9.8 citrix application_delivery_controller_firmware Unauthorized access to Gateway user capabilities 1.2%
CVE-2022-27479 CRIT 9.8 apache superset Apache Superset before 1.4.2 is vulnerable to SQL injection in chart data requests. Users should update to 1.4.2 or higher which addresses this issue. 2.9%
CVE-2022-27115 CRIT 9.8 std42 elfinder In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. 28.6%
CVE-2022-27007 CRIT 9.8 f5 njs nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). 1.6%
CVE-2022-26937 CRIT 9.8 microsoft windows_server Windows Network File System Remote Code Execution Vulnerability 76.5%
CVE-2022-26809 CRIT 9.8 microsoft windows_10 Remote Procedure Call Runtime Remote Code Execution Vulnerability 90.5%
CVE-2022-26612 CRIT 9.8 apache hadoop In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A sub 4.2%
CVE-2022-26184 CRIT 9.8 python-poetry poetry Poetry v1.1.9 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute Poetry commands in a directory containing malicious content. This vulnerability occurs when the application 1.9%
CVE-2022-26112 CRIT 9.8 apache pinot In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pin 1.4%
CVE-2022-25757 CRIT 9.8 apache apisix In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the last occurred value as the result. By passing a JSON with a duplicate key, the attacker can bypass the body_schema validation in the request-validation plugin. Fo 2.5%
CVE-2022-25371 CRIT 9.8 apache ofbiz Apache OFBiz uses the Birt project plugin (https://eclipse.github.io/birt-website/) to create data visualizations and reports. By leveraging a bug in Birt (https://bugs.eclipse.org/bugs/show_bug.cgi?id=538142) it is possible to perform a remote code execution 4.2%
CVE-2022-25330 CRIT 9.8 trendmicro serverprotect Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. 5.2%
CVE-2022-25329 CRIT 9.8 trendmicro serverprotect Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to 2.7%
CVE-2022-25168 CRIT 9.8 apache hadoop Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, which is only ever run b 4.1%
CVE-2022-25167 CRIT 9.8 apache flume Apache Flume versions 1.4.0 through 1.9.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JND 4.8%
CVE-2022-25139 CRIT 9.8 f5 njs njs through 0.7.0, used in NGINX, was discovered to contain a heap use-after-free in njs_await_fulfilled. 1.6%
CVE-2022-24963 CRIT 9.8 apache portable_runtime Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0. 1.5%
CVE-2022-24955 CRIT 9.8 foxit pdf_editor Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files. 1.1%
CVE-2022-24954 CRIT 9.8 foxit pdf_editor Foxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' and 'draw colSpan="1"' substrings. 11.9%
CVE-2022-24706 CRIT 9.8 apache couchdb In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including rec 92.4%
CVE-2022-24697 CRIT 9.8 apache kylin Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- conf=” to inject any op 84.8%