58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.450 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-41051 | HIGH 7.8 | microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41050 | HIGH 7.8 | microsoft windows_10 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-41048 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-41047 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-41045 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-41044 | HIGH 8.1 | microsoft windows_7 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41043 | LOW 3.3 | microsoft office Microsoft Office Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-41042 | HIGH 7.4 | microsoft visual_studio_code Visual Studio Code Information Disclosure Vulnerability | 2.0% | — |
| CVE-2022-41039 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-41038 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2022-41037 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-41036 | HIGH 8.8 | microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-41035 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.4% | — |
| CVE-2022-41034 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code Remote Code Execution Vulnerability | 67.5% | — |
| CVE-2022-41032 | HIGH 7.8 | fedoraproject fedora NuGet Client Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-41031 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-40955 | HIGH 8.8 | apache inlong In versions of Apache InLong prior to 1.3.0, an attacker with sufficient privileges to specify MySQL JDBC connection URL parameters and to write arbitrary data to the MySQL database, could cause this data to be deserialized by Apache InLong, potentially leadin | 2.7% | — |
| CVE-2022-40954 | MED 5.5 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Spark Provider, Apache Airflow allows an attacker to read arbtrary files in the task execution context, without write access to DAG files | 1.4% | — |
| CVE-2022-4095 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in Linux kernel before 5.19.2. This issue occurs in cmd_hdl_filter in drivers/staging/rtl8712/rtl8712_cmd.c, allowing an attacker to launch a local denial of service attack and gain escalation of privileges. | 0.3% | — |
| CVE-2022-40768 | MED 5.5 | debian debian_linux drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. | 0.3% | — |
| CVE-2022-40754 | MED 6.1 | apache airflow In Apache Airflow 2.3.0 through 2.3.4, there was an open redirect in the webserver's `/confirm` endpoint. | 1.7% | — |
| CVE-2022-40753 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus | 0.4% | — |
| CVE-2022-40752 | CRIT 9.8 | ibm infosphere_information_server IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. | 1.8% | — |
| CVE-2022-40750 | MED 5.4 | ibm websphere_application_server IBM WebSphere Application Server 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within | 0.4% | — |
| CVE-2022-40748 | MED 5.4 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust | 0.7% | — |