58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-23769 | HIGH 7.5 | megazone reversewall-mds Remote code execution vulnerability due to insufficient user privilege verification in reverseWall-MDS. Remote attackers can exploit the vulnerability such as stealing account, through remote code execution. | 1.0% | — |
| CVE-2022-23767 | HIGH 8.8 | hanssak securegate This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privile | 0.9% | — |
| CVE-2022-23766 | HIGH 7.8 | bigfile bigfileagent An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a gene | 0.6% | — |
| CVE-2022-23764 | HIGH 8.8 | teruten webcube The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution. | 0.7% | — |
| CVE-2022-23763 | HIGH 7.8 | douzone neors Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infection | 0.3% | — |
| CVE-2022-23742 | HIGH 7.8 | checkpoint endpoint_security Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpat | 4.2% | — |
| CVE-2022-23714 | HIGH 7.8 | elastic endpoint_security A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | 0.2% | — |
| CVE-2022-23678 | MED 5.9 | hp aruba_virtual_intranet_access A vulnerability in the Aruba Virtual Intranet Access (VIA) client for Microsoft Windows operating system client communications that could allow for an attacker in a privileged network position to intercept sensitive information in Aruba Virtual Intranet Access | 0.9% | — |
| CVE-2022-23551 | MED 5.3 | microsoft azure_ad_pod_identity aad-pod-identity assigns Azure Active Directory identities to Kubernetes applications and has now been deprecated as of 24 October 2022. The NMI component in AAD Pod Identity intercepts and validates token requests based on regex. In this case, a token request | 0.7% | — |
| CVE-2022-23511 | HIGH 7.1 | amazon cloudwatch_agent A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, | 0.5% | — |
| CVE-2022-23447 | HIGH 7.5 | fortinet fortiextender_firmware An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0 through 7.0.3, 4.2.0 through 4.2.4, 4.1.1 through 4.1.8, 4.0.0 through 4.0.2, 3.3.0 through 3.3.2, 3.2.1 throu | 0.8% | — |
| CVE-2022-23446 | MED 4.4 | fortinet fortiedr A improper control of a resource through its lifetime in Fortinet FortiEDR version 5.0.3 and earlier allows attacker to make the whole application unresponsive via changing its root directory access permission. | 0.2% | — |
| CVE-2022-23443 | HIGH 7.5 | fortinet fortisoar An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET requests. | 1.3% | — |
| CVE-2022-23442 | MED 4.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs | 0.6% | — |
| CVE-2022-23441 | CRIT 9.1 | fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker on the network to disguise as and forge messages from other collectors. | 0.9% | — |
| CVE-2022-23440 | HIGH 7.8 | fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deploy | 0.2% | — |
| CVE-2022-23439 | MED 4.7 | fortinet fortiadc A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver | 0.4% | — |
| CVE-2022-23438 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) | 0.7% | — |
| CVE-2022-23437 | MED 6.5 | apache xerces-j There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes consume system resources for prolonged durati | 11.6% | — |
| CVE-2022-23307 | HIGH 8.8 | apache chainsaw CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | 54.4% | — |
| CVE-2022-23305 | CRIT 9.8 | apache log4j By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate | 66.5% | — |
| CVE-2022-23302 | HIGH 8.8 | apache log4j JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a Topi | 63.6% | — |
| CVE-2022-23301 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23300 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-2330 | MED 6.5 | mcafee data_loss_prevention_endpoint Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constr | 0.9% | — |