58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-41836 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When an 'Attack Signature False Positive Mode' enabled security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. | 0.7% | — |
| CVE-2022-41833 | HIGH 7.5 | f5 big-ip_access_policy_manager In all BIG-IP 13.1.x versions, when an iRule containing the HTTP::collect command is configured on a virtual server, undisclosed requests can cause Traffic Management Microkernel (TMM) to terminate. | 0.7% | — |
| CVE-2022-41832 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when a SIP profile is configured on a virtual server, undisclosed messages can cause an increase in memory resource u | 0.7% | — |
| CVE-2022-41806 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager In versions 16.1.x before 16.1.3.2 and 15.1.x before 15.1.5.1, when BIG-IP AFM Network Address Translation policy with IPv6/IPv4 translation rules is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. | 0.7% | — |
| CVE-2022-41787 | HIGH 7.5 | f5 big-ip_domain_name_system In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, when DNS profile is configured on a virtual server with DNS Express enabled, undisclosed DNS queries with DNSSEC can | 0.7% | — |
| CVE-2022-41738 | HIGH 7.5 | ibm spectrum_scale_container_native_storage_access IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. | 0.4% | — |
| CVE-2022-41722 | HIGH 7.5 | golang go A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute pat | 1.7% | — |
| CVE-2022-41720 | HIGH 7.5 | golang go On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, o | 1.2% | — |
| CVE-2022-41716 | HIGH 7.5 | golang go Due to unsanitized NUL values, attackers may be able to maliciously set environment variables on Windows. In syscall.StartProcess and os/exec.Cmd, invalid environment variable values containing NUL values are not properly checked for. A malicious environment v | 0.8% | — |
| CVE-2022-41704 | HIGH 7.5 | apache batik A vulnerability in Batik of Apache XML Graphics allows an attacker to run untrusted Java code from an SVG. This issue affects Apache XML Graphics prior to 1.16. It is recommended to update to version 1.16. | 2.4% | — |
| CVE-2022-41691 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall When a BIG-IP Advanced WAF/ASM security policy is configured on a virtual server, undisclosed requests can cause the bd process to terminate. | 0.7% | — |
| CVE-2022-41624 | HIGH 7.5 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.2, 15.1.x before 15.1.7, 14.1.x before 14.1.5.2, and 13.1.x before 13.1.5.1, when a sideband iRule is configured on a virtual server, undisclosed traffic can cause an increase in memory resource u | 0.7% | — |
| CVE-2022-41333 | HIGH 7.5 | fortinet fortirecorder_firmware An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanism may allow an unauthenticated attacker to make the device unavailable via crafted GET requests. | 7.2% | — |
| CVE-2022-41118 | HIGH 7.5 | microsoft windows_10 Windows Scripting Languages Remote Code Execution Vulnerability | 1.2% | — |
| CVE-2022-41085 | HIGH 7.5 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-41058 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.1% | — |
| CVE-2022-41056 | HIGH 7.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability | 2.1% | — |
| CVE-2022-41053 | HIGH 7.5 | microsoft windows_10 Windows Kerberos Denial of Service Vulnerability | 2.1% | — |
| CVE-2022-40705 | HIGH 7.5 | apache soap An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files over HTTP. This issue affects Apache SOAP version 2.2 and later versions. It is unknown whether previous versio | 1.9% | — |
| CVE-2022-40676 | HIGH 7.5 | fortinet fortinac A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 all | 0.5% | — |
| CVE-2022-40604 | HIGH 7.5 | apache airflow In Apache Airflow 2.3.0 through 2.3.4, part of a url was unnecessarily formatted, allowing for possible information extraction. | 2.1% | — |
| CVE-2022-40308 | HIGH 7.5 | apache archiva If anonymous read enabled, it's possible to read the database file directly without logging in. | 1.3% | — |
| CVE-2022-40146 | HIGH 7.5 | apache batik Server-Side Request Forgery (SSRF) vulnerability in Batik of Apache XML Graphics allows an attacker to access files using a Jar url. This issue affects Apache XML Graphics Batik 1.14. | 7.4% | — |
| CVE-2022-40141 | HIGH 7.5 | trendmicro apex_one A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server. | 0.9% | — |
| CVE-2022-40082 | HIGH 7.5 | cloudwego hertz Hertz v0.3.0 ws discovered to contain a path traversal vulnerability via the normalizePath function. | 0.9% | — |