IT
58.450 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.450 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-38362 HIGH 8.8 apache apache-airflow-providers-docker Apache Airflow Docker's Provider prior to 3.0.0 shipped with an example DAG that was vulnerable to (authenticated) remote code exploit of code on the Airflow worker host. 1.9% —
CVE-2022-38221 CRIT 9.8 the_isle_evrima_project the_isle_evrima A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. 1.8% —
CVE-2022-38170 MED 4.7 apache airflow In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users t 0.6% —
CVE-2022-38166 HIGH 7.5 f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. 0.7% —
CVE-2022-38096 MED 6.3 linux linux_kernel A NULL pointer dereference vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to 0.8% —
CVE-2022-38054 CRIT 9.8 apache airflow In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. 2.1% —
CVE-2022-38053 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 76.4% —
CVE-2022-38051 HIGH 7.8 microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability 7.3% —
CVE-2022-38050 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 7.3% —
CVE-2022-38049 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0.9% —
CVE-2022-38048 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.6% —
CVE-2022-38047 HIGH 8.1 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 1.2% —
CVE-2022-38046 HIGH 7.5 microsoft windows_10 Web Account Manager Information Disclosure Vulnerability 1.9% —
CVE-2022-38045 HIGH 8.8 microsoft windows_10 Windows Server Service Elevation of Privilege Vulnerability 2.3% —
CVE-2022-38044 HIGH 7.8 microsoft windows_10 Windows CD-ROM File System Driver Remote Code Execution Vulnerability 56.3% —
CVE-2022-38043 MED 5.5 microsoft windows_10 Windows Security Support Provider Interface Information Disclosure Vulnerability 0.6% —
CVE-2022-38042 HIGH 7.1 microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability 1.4% —
CVE-2022-38041 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 2.2% —
CVE-2022-38040 HIGH 8.8 microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability 1.6% —
CVE-2022-38039 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6% —
CVE-2022-38038 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0% —
CVE-2022-38037 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0% —
CVE-2022-38036 HIGH 7.5 microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability 2.2% —
CVE-2022-38034 HIGH 8.8 microsoft windows_10 Windows Workstation Service Elevation of Privilege Vulnerability 3.2% —
CVE-2022-38033 MED 6.5 microsoft windows_10 Windows Server Remotely Accessible Registry Keys Information Disclosure Vulnerability 1.7% —