58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-26787 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26786 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26785 | MED 6.5 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 2.4% | — |
| CVE-2022-26784 | MED 6.5 | microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability | 2.4% | — |
| CVE-2022-26783 | MED 6.5 | microsoft windows_server_2016 Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability | 2.8% | — |
| CVE-2022-26779 | HIGH 7.5 | apache cloudstack Apache CloudStack prior to 4.16.1.0 used insecure random number generation for project invitation tokens. If a project invite is created based only on an email address, a random token is generated. An attacker with knowledge of the project ID and the fact that | 2.9% | — |
| CVE-2022-26659 | HIGH 7.1 | docker docker_desktop Docker Desktop installer on Windows in versions before 4.6.0 allows an attacker to overwrite any administrator writable files by creating a symlink in place of where the installer writes its log file. Starting from version 4.6.0, the Docker Desktop installer, | 0.4% | — |
| CVE-2022-26650 | HIGH 7.5 | apache shenyu In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions | 2.6% | — |
| CVE-2022-2663 | MED 5.3 | debian debian_linux An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured. | 3.2% | — |
| CVE-2022-26629 | CRIT 9.1 | splus soroushplus An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function. | 2.8% | — |
| CVE-2022-26612 | CRIT 9.8 | apache hadoop In Apache Hadoop, The unTar function uses unTarUsingJava function on Windows and the built-in tar utility on Unix and other OSes. As a result, a TAR entry may create a symlink under the expected extraction directory which points to an external directory. A sub | 4.2% | — |
| CVE-2022-26529 | MED 6.5 | realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for segmented packets’ link parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer overflow and d | 0.5% | — |
| CVE-2022-26528 | MED 6.5 | realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the length of segmented packets’ shift parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buffer | 0.5% | — |
| CVE-2022-26527 | MED 6.5 | realtek bluetooth_mesh_software_development_kit Realtek Linux/Android Bluetooth Mesh SDK has a buffer overflow vulnerability due to insufficient validation for the size of segmented packets’ reference parameter. An unauthenticated attacker in the adjacent network can exploit this vulnerability to cause buff | 0.5% | — |
| CVE-2022-26517 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when the BIG-IP CGNAT Large Scale NAT (LSN) pool is configured on a virtual server and packet filtering is enabled, undisclosed requests can | 0.8% | — |
| CVE-2022-26509 | LOW 2.5 | intel sgx_sdk Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access. | 0.2% | — |
| CVE-2022-26503 | HIGH 7.8 | veeam veeam Deserialization of untrusted data in Veeam Agent for Windows 2.0, 2.1, 2.2, 3.0.2, 4.x, and 5.x allows local users to run arbitrary code with local system privileges. | 0.7% | — |
| CVE-2022-26490 | HIGH 7.8 | debian debian_linux st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters. | 0.4% | — |
| CVE-2022-26488 | HIGH 7.0 | netapp active_iq_unified_manager In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have ins | 1.4% | — |
| CVE-2022-26477 | HIGH 7.5 | apache systemds The Security Team noticed that the termination condition of the for loop in the readExternal method is a controllable variable, which, if tampered with, may lead to CPU exhaustion. As a fix, we added an upper bound and termination condition in the read and wri | 2.2% | — |
| CVE-2022-26415 | HIGH 7.7 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x, when running in Appliance mode, an authenticated user assigned the Administrator | 0.7% | — |
| CVE-2022-2639 | HIGH 7.8 | linux linux_kernel An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potent | 0.9% | — |
| CVE-2022-26386 | MED 6.5 | mozilla firefox_esr Previously Firefox for macOS and Linux would download temporary files to a user-specific directory in <code>/tmp</code>, but this behavior was changed to download them to <code>/tmp</code> where they could be affected by other local users. This behavior was re | 0.7% | — |
| CVE-2022-26377 | HIGH 7.5 | apache http_server Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Ser | 21.1% | — |
| CVE-2022-26372 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.0.2, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when a DNS listener is configured on a virtual server with DNS queueing (default), undisclosed requests c | 0.9% | — |