58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted ascending |
|---|---|---|---|---|
| CVE-2022-24102 | HIGH 7.8 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of th | 12.6% | — |
| CVE-2022-24101 | LOW 3.3 | adobe acrobat Acrobat Reader DC versions 20.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to | 1.9% | — |
| CVE-2022-24099 | LOW 3.3 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Explo | 1.5% | — |
| CVE-2022-24098 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an improper input validation vulnerability when parsing a PCX file that could result in arbitrary code execution in the context of the current user. Exploitation of this issu | 2.8% | — |
| CVE-2022-24097 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.4% | — |
| CVE-2022-24096 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by an Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte | 3.9% | — |
| CVE-2022-24095 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte | 3.9% | — |
| CVE-2022-24094 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.2 (and earlier) and 18.4.4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user inte | 3.9% | — |
| CVE-2022-24092 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation | 4.5% | — |
| CVE-2022-24091 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation | 4.1% | — |
| CVE-2022-24090 | MED 5.5 | adobe photoshop Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Expl | 2.0% | — |
| CVE-2022-24070 | HIGH 7.5 | apache subversion Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). | 9.5% | — |
| CVE-2022-23974 | HIGH 7.5 | apache pinot In 0.9.3 or older versions of Apache Pinot segment upload path allowed segment directories to be imported into pinot tables. In pinot installations that allow open access to the controller a specially crafted request can potentially be exploited to cause disru | 2.1% | — |
| CVE-2022-23945 | HIGH 7.5 | apache shenyu Missing authentication on ShenYu Admin when register by HTTP. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 3.8% | — |
| CVE-2022-23944 | CRIT 9.1 | apache shenyu User can access /plugin api without authentication. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | 79.0% | — |
| CVE-2022-23943 | CRIT 9.8 | apache http_server Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. | 50.4% | — |
| CVE-2022-23942 | HIGH 7.5 | apache doris Apache Doris, prior to 1.0.0, used a hardcoded key and IV to initialize the cipher used for ldap password, which may lead to information disclosure. | 3.5% | — |
| CVE-2022-23913 | HIGH 7.5 | apache artemis In Apache ActiveMQ Artemis prior to 2.20.0 or 2.19.1, an attacker could partially disrupt availability (DoS) through uncontrolled resource consumption of memory. | 2.7% | — |
| CVE-2022-23909 | HIGH 7.8 | gimmal sherpa_connector_service There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file. | 1.0% | — |
| CVE-2022-23831 | HIGH 7.5 | amd amd_uprof Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service. | 0.7% | — |
| CVE-2022-23825 | MED 6.5 | amd a10-9600p_firmware Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | 0.8% | — |
| CVE-2022-23805 | HIGH 7.1 | trendmicro worry-free_business_security A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server could allow a local attacker to send garbage data to a specific named pipe and crash the server. Please note: an attacker must first obtain th | 0.7% | — |
| CVE-2022-2380 | MED 5.5 | linux linux_kernel The Linux kernel was found vulnerable out of bounds memory access in the drivers/video/fbdev/sm712fb.c:smtcfb_read() function. The vulnerability could result in local attackers being able to crash the kernel. | 0.2% | — |
| CVE-2022-23774 | MED 5.3 | docker docker_desktop Docker Desktop before 4.4.4 on Windows allows attackers to move arbitrary files. | 0.9% | — |
| CVE-2022-23770 | HIGH 8.8 | wisa smart_wing_cms This vulnerability could allow a remote attacker to execute remote commands with improper validation of parameters of certain API constructors. Remote attackers could use this vulnerability to execute malicious commands such as directory traversal. | 1.5% | — |