IT
58.515 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.515 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sorted ascending
CVE-2022-21842 HIGH 7.8 microsoft sharepoint_enterprise_server Microsoft Word Remote Code Execution Vulnerability 2.3% —
CVE-2022-21841 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 2.6% —
CVE-2022-21840 HIGH 8.8 microsoft excel Microsoft Office Remote Code Execution Vulnerability 3.1% —
CVE-2022-21839 MED 6.1 microsoft windows_10 Windows Event Tracing Discretionary Access Control List Denial of Service Vulnerability 1.5% —
CVE-2022-21838 MED 5.5 microsoft windows_10 Windows Cleanup Manager Elevation of Privilege Vulnerability 1.5% —
CVE-2022-21837 HIGH 8.3 microsoft sharepoint_foundation Microsoft SharePoint Server Remote Code Execution Vulnerability 3.0% —
CVE-2022-21836 HIGH 7.8 microsoft windows_10 Windows Certificate Spoofing Vulnerability 0.7% —
CVE-2022-21835 HIGH 7.8 microsoft windows_10 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0.7% —
CVE-2022-21834 HIGH 7.0 microsoft windows_10 Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability 0.6% —
CVE-2022-21833 HIGH 7.8 microsoft windows_10 Virtual Machine IDE Drive Elevation of Privilege Vulnerability 0.6% —
CVE-2022-21827 HIGH 7.1 citrix gateway_plug-in An improper privilege vulnerability has been discovered in Citrix Gateway Plug-in for Windows (Citrix Secure Access for Windows) <21.9.1.2 what could allow an attacker who has gained local access to a computer with Citrix Gateway Plug-in installed, to corrupt 0.2% —
CVE-2022-21825 HIGH 7.8 citrix workspace An Improper Access Control vulnerability exists in Citrix Workspace App for Linux 2012 - 2111 with App Protection installed that can allow an attacker to perform local privilege escalation. 0.2% —
CVE-2022-21821 HIGH 7.8 nvidia cuda_toolkit NVIDIA CUDA Toolkit SDK contains an integer overflow vulnerability in cuobjdump.To exploit this vulnerability, a remote attacker would require a local user to download a specially crafted, corrupted file and locally execute cuobjdump against the file. Such an 2.1% —
CVE-2022-21820 MED 6.3 nvidia data_center_gpu_manager NVIDIA DCGM contains a vulnerability in nvhostengine, where a network user can cause detection of error conditions without action, which may lead to limited code execution, some denial of service, escalation of privileges, and limited impacts to both data conf 16.5% —
CVE-2022-21817 CRIT 9.3 nvidia omniverse_launcher NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other security 1.7% —
CVE-2022-21815 MED 5.5 nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a sy 0.2% —
CVE-2022-21813 MED 6.1 nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver, where improper handling of insufficient permissions or privileges may allow an unprivileged local user limited write access to protected memory, which can lead to denial of serv 0.2% —
CVE-2022-21793 MED 5.5 vmware i40en Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to poten 0.2% —
CVE-2022-2170 MED 4.8 microsoft microsoft_advertising_universal_event_tracking The Microsoft Advertising Universal Event Tracking (UET) WordPress plugin before 1.0.4 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is di 1.4% —
CVE-2022-2162 HIGH 8.8 fedoraproject fedora Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. 1.3% —
CVE-2022-2160 MED 6.5 fedoraproject fedora Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML pa 0.7% —
CVE-2022-21546 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: Fix WRITE_SAME No Data Buffer crash In newer version of the SBC specs, we have a NDOB bit that indicates there is no data buffer that gets written out. If this bit is set using 0.4% —
CVE-2022-2153 MED 5.5 debian debian_linux A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to 0.5% —
CVE-2022-21221 MED 5.9 fasthttp_project fasthttp The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue i 2.5% —
CVE-2022-21166 MED 5.5 debian debian_linux Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. 5.8% —