58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-27181 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when APM is configured on a virtual server and the associated acce | 0.9% | — |
| CVE-2022-27166 | MED 6.1 | apache jspwiki A carefully crafted request on XHRHtml2Markup.jsp could trigger an XSS vulnerability on Apache JSPWiki up to and including 2.11.2, which could allow the attacker to execute javascript in the victim's browser and get some sensitive information about the victim. | 85.8% | — |
| CVE-2022-27115 | CRIT 9.8 | std42 elfinder In Studio-42 elFinder 2.1.60, there is a vulnerability that causes remote code execution through file name bypass for file upload. | 28.6% | — |
| CVE-2022-27050 | HIGH 7.8 | bitcomet bitcomet BitComet Service for Windows before version 1.8.6 contains an unquoted service path vulnerability which allows attackers to escalate privileges to the system level. | 0.4% | — |
| CVE-2022-27008 | HIGH 7.5 | f5 njs nginx njs 0.7.2 is vulnerable to Buffer Overflow. Type confused in Array.prototype.concat() when a slow array appended element is fast array. | 1.7% | — |
| CVE-2022-27007 | CRIT 9.8 | f5 njs nginx njs 0.7.2 is affected suffers from Use-after-free in njs_function_frame_alloc() when it try to invoke from a restored frame saved with njs_function_frame_save(). | 1.6% | — |
| CVE-2022-26979 | HIGH 7.5 | foxit pdf_editor Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. | 1.1% | — |
| CVE-2022-26966 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.16.12. drivers/net/usb/sr9700.c allows attackers to obtain sensitive information from heap memory via crafted frame lengths from a device. | 0.3% | — |
| CVE-2022-26940 | MED 6.5 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.7% | — |
| CVE-2022-26939 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-26938 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26937 | CRIT 9.8 | microsoft windows_server Windows Network File System Remote Code Execution Vulnerability | 76.0% | — |
| CVE-2022-26936 | MED 6.5 | microsoft windows_10 Windows Server Service Information Disclosure Vulnerability | 3.1% | — |
| CVE-2022-26935 | MED 6.5 | microsoft windows_10 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 1.1% | — |
| CVE-2022-26934 | MED 6.5 | microsoft 365_apps Windows Graphics Component Information Disclosure Vulnerability | 3.1% | — |
| CVE-2022-26933 | MED 5.5 | microsoft windows_10 Windows NTFS Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-26932 | HIGH 8.2 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-26931 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Elevation of Privilege Vulnerability | 2.7% | — |
| CVE-2022-26930 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2022-26929 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-26928 | HIGH 7.0 | microsoft windows_10 Windows Photo Import API Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26927 | HIGH 8.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 4.6% | — |
| CVE-2022-26926 | HIGH 7.8 | microsoft windows_10 Windows Address Book Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-26924 | HIGH 7.5 | microsoft yet_another_reverse_proxy YARP Denial of Service Vulnerability | 3.5% | — |
| CVE-2022-26921 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability | 0.6% | — |