IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-27964 MED 6.5 netsarang xmanager Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. 0.5%
CVE-2022-27963 MED 6.5 netsarang xftp Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. 0.4%
CVE-2022-27634 MED 6.5 f5 big-ip_access_policy_manager On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leading to privilege escalation/remote code e 1.4%
CVE-2022-27507 MED 6.5 citrix application_delivery_controller Authenticated denial of service 1.0%
CVE-2022-27495 MED 6.5 f5 nginx_service_mesh On all versions 1.3.x (fixed in 1.4.0) NGINX Service Mesh control plane endpoints are exposed to the cluster overlay network. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.3%
CVE-2022-27485 MED 6.5 fortinet fortisandbox A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0, 4.0.0 through 4.0.2, 3.2.0 through 3.2.3, 3.1.x and 3.0.x allows a remote and authenticated attacker with read 0.6%
CVE-2022-26940 MED 6.5 microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability 2.5%
CVE-2022-26936 MED 6.5 microsoft windows_10 Windows Server Service Information Disclosure Vulnerability 2.9%
CVE-2022-26935 MED 6.5 microsoft windows_10 Windows WLAN AutoConfig Service Information Disclosure Vulnerability 1.0%
CVE-2022-26934 MED 6.5 microsoft 365_apps Windows Graphics Component Information Disclosure Vulnerability 2.9%
CVE-2022-26911 MED 6.5 microsoft lync_server Skype for Business Information Disclosure Vulnerability 3.6%
CVE-2022-26884 MED 6.5 apache dolphinscheduler Users can read any files by log server, Apache DolphinScheduler users should upgrade to version 2.0.6 or higher. 1.6%
CVE-2022-26816 MED 6.5 microsoft windows_server_2016 Windows DNS Server Information Disclosure Vulnerability 2.5%
CVE-2022-26785 MED 6.5 microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability 2.4%
CVE-2022-26784 MED 6.5 microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability 2.4%
CVE-2022-26783 MED 6.5 microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability 2.8%
CVE-2022-26529 MED 6.5 realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and d 0.5%
CVE-2022-26528 MED 6.5 realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer 0.5%
CVE-2022-26527 MED 6.5 realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buff 0.5%
CVE-2022-26386 MED 6.5 mozilla firefox_esr Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was re 0.7%
CVE-2022-26240 MED 6.5 beckmancoulter remisol_advance The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data. 0.6%
CVE-2022-2622 MED 6.5 fedoraproject fedora Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file. 0.7%
CVE-2022-25635 MED 6.5 realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for broadcast network packet length. An unauthenticated attacker in the adjacent network can exploit this vulnerability to disrupt service. 0.4%
CVE-2022-25147 MED 6.5 apache portable_runtime_utility Integer Overflow or Wraparound vulnerability in apr_base64 functions of Apache Portable Runtime Utility (APR-util) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime Utility (APR-util) 1.6.1 and prior versions 1.4%
CVE-2022-24960 MED 6.5 pdftron pdftron A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron PDFTron SDK 9.2.0 on OSX; 9.2.0 on Linux; 9.2.0 on Windows. 0.6%