57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24538 | MED 6.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-24522 | MED 6.5 | microsoft skype_extension Skype Extension for Chrome Information Disclosure Vulnerability | 2.3% | — |
| CVE-2022-24519 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24518 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24515 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24506 | MED 6.5 | microsoft azure_site_recovery Azure Site Recovery Elevation of Privilege Vulnerability | 2.8% | — |
| CVE-2022-24498 | MED 6.5 | microsoft windows_10 Windows iSCSI Target Service Information Disclosure Vulnerability | 2.6% | — |
| CVE-2022-24463 | MED 6.5 | microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability | 31.8% | — |
| CVE-2022-24368 | MED 6.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 2.1% | — |
| CVE-2022-24280 | MED 6.5 | apache pulsar Improper Input Validation vulnerability in Proxy component of Apache Pulsar allows an attacker to make TCP/IP connection attempts that originate from the Pulsar Proxy's IP address. When the Apache Pulsar Proxy component is used, it is possible to attempt to op | 1.3% | — |
| CVE-2022-23825 | MED 6.5 | amd a10-9600p_firmware Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | 0.8% | — |
| CVE-2022-23437 | MED 6.5 | apache xerces-j There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged durati | 11.6% | — |
| CVE-2022-2330 | MED 6.5 | mcafee data_loss_prevention_endpoint Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constr | 0.9% | — |
| CVE-2022-23271 | MED 6.5 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 3.8% | — |
| CVE-2022-23268 | MED 6.5 | microsoft windows_11 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-23253 | MED 6.5 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 56.4% | — |
| CVE-2022-23238 | MED 6.5 | netapp storagegrid Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metric | 0.7% | — |
| CVE-2022-2308 | MED 6.5 | linux linux_kernel A flaw was found in vDPA with VDUSE backend. There are currently no checks in VDUSE kernel driver to ensure the size of the device config space is in line with the features advertised by the VDUSE userspace application. In case of a mismatch, Virtio drivers co | 0.2% | — |
| CVE-2022-23023 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory r | 0.9% | — |
| CVE-2022-23014 | MED 6.5 | f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End o | 0.8% | — |
| CVE-2022-22971 | MED 6.5 | netapp cloud_secure_agent In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | 3.2% | — |
| CVE-2022-22953 | MED 6.5 | vmware vmware_hcx VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information. | 0.8% | — |
| CVE-2022-22950 | MED 6.5 | vmware spring_framework n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition. | 36.1% | — |
| CVE-2022-22948 | MED 6.5 | vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. | 13.3% | |
| CVE-2022-22938 | MED 6.5 | vmware horizon VMware Workstation (16.x prior to 16.2.2) and Horizon Client for Windows (5.x prior to 5.5.3) contains a denial-of-service vulnerability in the Cortado ThinPrint component. The issue exists in TrueType font parser. A malicious actor with access to a virtual ma | 0.4% | — |