57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41813 | MED 6.5 | f5 big-ip_advanced_firewall_manager In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate. | 0.6% | — |
| CVE-2022-41770 | MED 6.5 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource ut | 0.6% | — |
| CVE-2022-41553 | MED 6.5 | hitachi infrastructure_analytics_advisor Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain | 0.2% | — |
| CVE-2022-41294 | MED 6.5 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | 0.3% | — |
| CVE-2022-41291 | MED 6.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. | 0.4% | — |
| CVE-2022-41122 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.6% | — |
| CVE-2022-41097 | MED 6.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability | 1.6% | — |
| CVE-2022-40675 | MED 6.5 | fortinet fortinac Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an attacker to decrypt and forge protoco | 0.4% | — |
| CVE-2022-40235 | MED 6.5 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 could allow a user to cause a denial of service by removing the ability to run jobs due to improper input validation. IBM X-Force ID: 235725." | 0.6% | — |
| CVE-2022-40160 | MED 6.5 | apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then | 1.3% | — |
| CVE-2022-40159 | MED 6.5 | apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then | 1.3% | — |
| CVE-2022-38033 | MED 6.5 | microsoft windows_10 Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability | 1.6% | — |
| CVE-2022-38015 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-38006 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 2.3% | — |
| CVE-2022-38001 | MED 6.5 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 1.5% | — |
| CVE-2022-37977 | MED 6.5 | microsoft windows_10 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability | 1.9% | — |
| CVE-2022-37974 | MED 6.5 | microsoft windows_10 Windows Mixed Reality Developer Tools Information Disclosure Vulnerability | 36.3% | — |
| CVE-2022-37959 | MED 6.5 | microsoft windows_server_2012 Network Device Enrollment Service (NDES) Security Feature Bypass Vulnerability | 2.4% | — |
| CVE-2022-37424 | MED 6.5 | opennebula opennebula Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. | 0.8% | — |
| CVE-2022-37023 | MED 6.5 | apache geode Apache Geode versions prior to 1.15.0 are vulnerable to a deserialization of untrusted data flaw when using REST API on Java 8 or Java 11. Any user wishing to protect against deserialization attacks involving REST APIs should upgrade to Apache Geode 1.15 and f | 1.6% | — |
| CVE-2022-36772 | MED 6.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user. | 0.6% | — |
| CVE-2022-3643 | MED 6.5 | debian debian_linux Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest | 0.5% | — |
| CVE-2022-35837 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 2.5% | — |
| CVE-2022-35819 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 1.9% | — |
| CVE-2022-35818 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 1.9% | — |