57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-31681 | MED 6.5 | vmware cloud_foundation VMware ESXi contains a null-pointer deference vulnerability. A malicious actor with privileges within the VMX process only, may create a denial of service condition on the host. | 0.2% | — |
| CVE-2022-30607 | MED 6.5 | ibm robotic_process_automation IBM Robotic Process Automation 20.10.0, 20.12.5, 21.0.0, 21.0.1, and 21.0.2 contains a vulnerability that could allow a user to obtain sensitive information due to information properly masked in the control center UI. IBM X-Force ID: 227294. | 0.7% | — |
| CVE-2022-30535 | MED 6.5 | f5 nginx_ingress_controller In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are no | 0.7% | — |
| CVE-2022-30302 | MED 6.5 | fortinet fortideceptor Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlyi | 0.9% | — |
| CVE-2022-30300 | MED 6.5 | fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. | 0.8% | — |
| CVE-2022-30208 | MED 6.5 | microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-30189 | MED 6.5 | microsoft windows_10 Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability | 2.7% | — |
| CVE-2022-30181 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 1.8% | — |
| CVE-2022-30134 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 2.0% | — |
| CVE-2022-29405 | MED 6.5 | apache archiva In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 | 1.7% | — |
| CVE-2022-29134 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29123 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29122 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29121 | MED 6.5 | microsoft windows_10 Windows WLAN AutoConfig Service Denial of Service Vulnerability | 0.9% | — |
| CVE-2022-29120 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29112 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 3.2% | — |
| CVE-2022-28859 | MED 6.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1 and 14.1.x versions prior to 14.1.4.6, when installing Net HSM, the scripts (nethsm-safenet-install.sh and nethsm-thales-install.sh) expose the Net HSM partition password. Note: Software versions which have reache | 0.8% | — |
| CVE-2022-28731 | MED 6.5 | apache jspwiki A carefully crafted request on UserPreferences.jsp could trigger an CSRF vulnerability on Apache JSPWiki before 2.11.3, which could allow the attacker to modify the email associated with the attacked account, and then a reset password request from the login pa | 56.9% | — |
| CVE-2022-2856 | MED 6.5 | fedoraproject fedora Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker to arbitrarily browse to a malicious website via a crafted HTML page. | 4.5% | |
| CVE-2022-28199 | MED 6.5 | nvidia data_plane_development_kit NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and | 2.2% | — |
| CVE-2022-28148 | MED 6.5 | jenkins continuous_integration_with_toad_edge The file browser in Jenkins Continuous Integration with Toad Edge Plugin 2.3 and earlier may interpret some paths to files as absolute on Windows, resulting in a path traversal vulnerability allowing attackers with Item/Read permission to obtain the contents o | 1.8% | — |
| CVE-2022-27966 | MED 6.5 | netsarang xshell Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.5% | — |
| CVE-2022-27965 | MED 6.5 | netsarang xlpd Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.5% | — |
| CVE-2022-27964 | MED 6.5 | netsarang xmanager Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.5% | — |
| CVE-2022-27963 | MED 6.5 | netsarang xftp Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. | 0.4% | — |