IT
58.450 CVE tracked
793 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.450 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-36122 HIGH 7.8 automox automox The Automox Agent before 40 on Windows incorrectly sets permissions on key files. 0.2% —
CVE-2022-36088 MED 5.0 thoughtworks gocd GoCD is a continuous delivery server. Windows installations via either the server or agent installers for GoCD prior to 22.2.0 do not adequately restrict permissions when installing outside of the default location. This could allow a malicious user with local 0.2% —
CVE-2022-36077 HIGH 7.2 electronjs electron The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, 0.6% —
CVE-2022-36070 HIGH 7.3 python-poetry poetry Poetry is a dependency manager for Python. To handle dependencies that come from a Git repository, Poetry executes various commands, e.g. `git config`. These commands are being executed using the executable’s name and not its absolute path. This can lead to th 0.4% —
CVE-2022-3606 LOW 3.5 linux linux_kernel A vulnerability was found in Linux Kernel. It has been classified as problematic. This affects the function find_prog_by_sec_insn of the file tools/lib/bpf/libbpf.c of the component BPF. The manipulation leads to null pointer dereference. It is recommended to 0.3% —
CVE-2022-3595 LOW 3.5 linux linux_kernel A vulnerability was found in Linux Kernel. It has been rated as problematic. Affected by this issue is the function sess_free_buffer of the file fs/cifs/sess.c of the component CIFS Handler. The manipulation leads to double free. It is recommended to apply a p 0.3% —
CVE-2022-3594 MED 5.3 debian debian_linux A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The atta 2.5% —
CVE-2022-35899 HIGH 7.8 asus aura_ready_game_software_development_kit There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file. 0.9% —
CVE-2022-3586 MED 5.5 debian debian_linux A flaw was found in the Linux kernel’s networking code. A use-after-free was found in the way the sch_sfb enqueue function used the socket buffer (SKB) cb field after the same SKB had been enqueued (and freed) into a child qdisc. This flaw allows a local, unpr 0.5% —
CVE-2022-35851 HIGH 8.0 fortinet fortiadc An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and authenticated attacker to trigger a stored cross site scripting (XSS) attack via configuring a specially crafted 0.5% —
CVE-2022-35850 MED 4.3 fortinet fortiauthenticator An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0 through 6.3.3, all versions of 6.2 and 6.1 may allow a remote unauthenticated attacker to trigger a reflected 0.5% —
CVE-2022-35849 HIGH 7.8 fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to exe 0.5% —
CVE-2022-35847 MED 6.3 fortinet fortisoar An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute arbitrary code via a cr 0.8% —
CVE-2022-35846 HIGH 8.1 fortinet fortitester An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to guess the credentials of an admin user via a 0.8% —
CVE-2022-35845 HIGH 7.8 fortinet fortitester Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitra 1.1% —
CVE-2022-35844 MED 6.7 fortinet fortitester An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an authenticated attacker to execute unauthorized com 0.3% —
CVE-2022-35843 HIGH 8.1 fortinet fortios An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 th 0.9% —
CVE-2022-35842 LOW 3.7 fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP an 0.7% —
CVE-2022-35841 HIGH 8.8 microsoft windows_10 Windows Enterprise App Management Service Remote Code Execution Vulnerability 3.6% —
CVE-2022-35840 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.2% —
CVE-2022-35838 HIGH 7.5 microsoft windows_11 HTTP V3 Denial of Service Vulnerability 2.7% —
CVE-2022-35837 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 2.5% —
CVE-2022-35836 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.2% —
CVE-2022-35835 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.2% —
CVE-2022-35834 HIGH 8.8 microsoft windows_10 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability 2.2% —