IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-29479 MED 5.3 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configu 0.9% —
CVE-2022-29474 MED 4.3 f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, a directory traversal vulnerability exists in iControl SOAP that allow 1.6% —
CVE-2022-29473 MED 5.9 f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an IPSec ALG profile is configured on a virtual server, undisclosed responses can cause Traffic Management Microkernel(TMM) to terminat 0.8% —
CVE-2022-29405 MED 6.5 apache archiva In Apache Archiva, any registered user can reset password for any users. This is fixed in Archiva 2.2.8 1.7% —
CVE-2022-29404 HIGH 7.5 apache http_server In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. 6.2% —
CVE-2022-2938 HIGH 7.8 fedoraproject fedora A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects. 0.3% —
CVE-2022-29379 CRIT 9.8 f5 njs Nginx NJS v0.7.3 was discovered to contain a stack overflow in the function njs_default_module_loader at /src/njs/src/njs_module.c. NOTE: multiple third parties dispute this report, e.g., the behavior is only found in unreleased development code that was not p 1.8% —
CVE-2022-29376 HIGH 8.8 apachefriends xampp Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. 1.4% —
CVE-2022-29369 HIGH 7.5 f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. 1.2% —
CVE-2022-29266 HIGH 7.5 apache apisix In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information. 8.1% —
CVE-2022-29265 HIGH 7.5 apache nifi Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The followi 2.6% —
CVE-2022-29263 HIGH 7.8 f5 access_policy_manager_clients On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, th 0.2% —
CVE-2022-29158 HIGH 7.5 apache ofbiz Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 2.0% —
CVE-2022-29156 HIGH 7.8 linux linux_kernel drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. 0.4% —
CVE-2022-29151 HIGH 7.0 microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability 0.6% —
CVE-2022-29150 HIGH 7.0 microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability 0.6% —
CVE-2022-29149 HIGH 7.8 microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability 0.9% —
CVE-2022-29148 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 2.8% —
CVE-2022-29147 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.6% —
CVE-2022-29146 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0% —
CVE-2022-29145 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 5.4% —
CVE-2022-29144 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0% —
CVE-2022-29143 HIGH 7.5 microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability 1.9% —
CVE-2022-29142 HIGH 7.0 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 5.1% —
CVE-2022-29141 HIGH 8.8 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.8% —