IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted descending
CVE-2022-29112 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 3.5% —
CVE-2022-29111 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.5% —
CVE-2022-29110 HIGH 7.8 microsoft excel Microsoft Excel Remote Code Execution Vulnerability 3.8% —
CVE-2022-29109 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.8% —
CVE-2022-29108 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Remote Code Execution Vulnerability 11.1% —
CVE-2022-29107 MED 5.5 microsoft 365_apps Microsoft Office Security Feature Bypass Vulnerability 3.1% —
CVE-2022-29106 HIGH 7.0 microsoft windows_10 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability 0.6% —
CVE-2022-29105 HIGH 7.8 microsoft windows_10 Microsoft Windows Media Foundation Remote Code Execution Vulnerability 2.8% —
CVE-2022-29104 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 11.8% —
CVE-2022-29103 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6% —
CVE-2022-29102 MED 5.5 microsoft windows_server Windows Failover Cluster Information Disclosure Vulnerability 0.9% —
CVE-2022-29072 HIGH 7.8 7-zip 7-zip 7-Zip through 21.07 on Windows allows privilege escalation and command execution when a file with the .7z extension is dragged to the Help>Contents area. This is caused by misconfiguration of 7z.dll and a heap overflow. The command runs in a child process unde 1.5% —
CVE-2022-29063 CRIT 9.8 apache ofbiz The Solr plugin of Apache OFBiz is configured by default to automatically make a RMI request on localhost, port 1099. In version 18.12.05 and earlier, by hosting a malicious RMI server on localhost, an attacker may exploit this behavior, at server start-up or 4.8% —
CVE-2022-29062 MED 6.3 fortinet fortisoar Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests. 0.8% —
CVE-2022-29061 HIGH 7.2 fortinet fortisoar An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests. 1.6% —
CVE-2022-29060 HIGH 8.1 fortinet fortiddos A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device. 0.7% —
CVE-2022-29059 LOW 2.7 fortinet fortiweb An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over 0.4% —
CVE-2022-29058 HIGH 7.8 fortinet fortiap An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP 6.0.0 through 6.4.7, 7.0.0 through 7.0.3, 7.2.0, FortiAP-S 6.0.0 through 6.4.7, FortiAP-W2 6.0.0 through 6.4.7, 7.0. 0.5% —
CVE-2022-29057 MED 5.4 fortinet fortiedr A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch 6 and 4.0.0 allows a remote authenticated attacker to perform a reflected cross site scripting attack (XSS) by 0.6% —
CVE-2022-29056 LOW 3.7 fortinet fortimail A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via sending nume 1.8% —
CVE-2022-29055 HIGH 7.5 fortinet fortios A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated atta 1.0% —
CVE-2022-29054 LOW 3.3 fortinet fortios A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the DHCP and DNS keys in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.9, 6.2.x and 6.0.x may allow an attacker in possession of the encrypted key to d 0.2% —
CVE-2022-29053 LOW 2.3 fortinet fortios A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it. 0.3% —
CVE-2022-2905 MED 5.5 debian debian_linux An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data. 0.4% —
CVE-2022-28944 HIGH 8.8 emcosoftware msi_package_builder Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7. 1.5% —