58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sorted descending |
|---|---|---|---|---|
| CVE-2022-23272 | HIGH 8.1 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 2.5% | — |
| CVE-2022-23271 | MED 6.5 | microsoft dynamics_gp Microsoft Dynamics GP Elevation Of Privilege Vulnerability | 3.8% | — |
| CVE-2022-23270 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 70.3% | — |
| CVE-2022-2327 | HIGH 7.5 | linux linux_kernel io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts whic | 0.3% | — |
| CVE-2022-23269 | MED 5.4 | microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability | 1.2% | — |
| CVE-2022-23268 | MED 6.5 | microsoft windows_11 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-23267 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5.7% | — |
| CVE-2022-23266 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-23265 | HIGH 7.2 | microsoft defender_for_iot Microsoft Defender for IoT Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-23264 | MED 4.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.7% | — |
| CVE-2022-23263 | HIGH 7.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-23262 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2022-23261 | MED 5.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Tampering Vulnerability | 1.6% | — |
| CVE-2022-23259 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.9% | — |
| CVE-2022-23258 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 1.6% | — |
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-23256 | HIGH 8.1 | microsoft azure_data_explorer Azure Data Explorer Spoofing Vulnerability | 1.6% | — |
| CVE-2022-23255 | MED 5.9 | microsoft onedrive Microsoft OneDrive for Android Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-23254 | MED 4.9 | microsoft powerbi-client_js_sdk Microsoft Power BI Information Disclosure Vulnerability | 2.6% | — |
| CVE-2022-23253 | MED 6.5 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 56.4% | — |
| CVE-2022-23252 | MED 5.5 | microsoft 365_apps Microsoft Office Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-23238 | MED 6.5 | netapp storagegrid Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metric | 0.7% | — |
| CVE-2022-23223 | HIGH 7.5 | apache shenyu On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later. | 4.3% | — |
| CVE-2022-23222 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. | 1.9% | — |
| CVE-2022-23206 | HIGH 7.5 | apache traffic_control In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oauth to scan a port of a server that Traffic Ops can reach. | 2.0% | — |