57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22179 | MED 6.5 | juniper junos A Improper Validation of Specified Index, Position, or Offset in Input vulnerability in the Juniper DHCP daemon (jdhcpd) of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a crash of jdhcpd and thereby a Denial of Service (DoS). | 0.4% | — |
| CVE-2022-22172 | MED 6.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Layer-2 control protocols daemon (l2cpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated adjacent attacker to cause a memory leak. Continued exploitation can | 0.4% | — |
| CVE-2022-22168 | MED 6.5 | juniper junos An Improper Validation of Specified Type of Input vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to trigger a Missing Release of Memory after Effective Lifetime vulnerability. Continued exploitation of this | 0.4% | — |
| CVE-2022-22166 | MED 6.5 | juniper junos An Improper Validation of Specified Quantity in Input vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause an rdp crash and thereby a Denial of Service (DoS). If a BGP update mess | 0.4% | — |
| CVE-2022-22164 | MED 6.5 | juniper junos_os_evolved An Improper Initialization vulnerability in Juniper Networks Junos OS Evolved may cause a commit operation for disabling the telnet service to not take effect as expected, resulting in the telnet service staying enabled. When it is not intended to be operating | 0.7% | — |
| CVE-2022-22160 | MED 6.5 | juniper junos An Unchecked Error Condition vulnerability in the subscriber management daemon (smgd) of Juniper Networks Junos OS allows an unauthenticated adjacent attacker to cause a crash of and thereby a Denial of Service (DoS). In a subscriber management / broadband edg | 0.4% | — |
| CVE-2022-22156 | MED 6.5 | juniper junos An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may compromise the integrity and | 0.5% | — |
| CVE-2022-22155 | MED 6.5 | juniper junos An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Networks Junos OS allows an adjacent attacker to cause a memory leak in the Flexible PIC Concentrator (FPC) of an ACX5448 router. The continuous | 0.4% | — |
| CVE-2022-22042 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 2.6% | — |
| CVE-2022-22015 | MED 6.5 | microsoft remote_desktop_client Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | 2.5% | — |
| CVE-2022-21918 | MED 6.5 | microsoft windows_10 DirectX Graphics Kernel File Denial of Service Vulnerability | 1.1% | — |
| CVE-2022-21915 | MED 6.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 2.7% | — |
| CVE-2022-2188 | MED 6.5 | mcafee data_exchange_layer Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker. | 0.1% | — |
| CVE-2022-21847 | MED 6.5 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 1.0% | — |
| CVE-2022-2160 | MED 6.5 | fedoraproject fedora Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML pa | 0.7% | — |
| CVE-2022-20949 | MED 6.5 | cisco secure_firewall_threat_defense A vulnerability in the management web server of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker with high privileges to execute configuration commands on an affected system. This vulnerability exists because acces | 0.7% | — |
| CVE-2022-20942 | MED 6.5 | cisco asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attack | 0.9% | — |
| CVE-2022-20931 | MED 6.5 | cisco telepresence_collaboration_endpoint A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device. This vulnerability is due to ins | 0.3% | — |
| CVE-2022-20859 | MED 6.5 | cisco unified_communications_manager A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attac | 1.2% | — |
| CVE-2022-20828 | MED 6.5 | cisco asa_firepower A vulnerability in the CLI parser of Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected ASA FirePOWER mod | 49.3% | — |
| CVE-2022-20821 | MED 6.5 | cisco ios_xr A vulnerability in the health check RPM of Cisco IOS XR Software could allow an unauthenticated, remote attacker to access the Redis instance that is running within the NOSi container. This vulnerability exists because the health check RPM opens TCP port 6379 | 12.1% | |
| CVE-2022-20819 | MED 6.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege leve | 1.0% | — |
| CVE-2022-20816 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to delete arbitrary fi | 1.2% | — |
| CVE-2022-20810 | MED 6.5 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to insufficient | 0.7% | — |
| CVE-2022-20796 | MED 6.5 | cisco secure_endpoint On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticat | 0.4% | — |