IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-39337 HIGH 7.5 apache hertzbeat Hertzbeat is an open source, real-time monitoring system with custom-monitoring, high performance cluster, prometheus-like and agentless. Hertzbeat versions 1.20 and prior have a permission bypass vulnerability. System authentication can be bypassed and invoke 1.1% —
CVE-2022-38370 HIGH 7.5 apache iotdb Apache IoTDB grafana-connector version 0.13.0 contains an interface without authorization, which may expose the internal structure of database. Users should upgrade to version 0.13.1 which addresses this issue. 1.3% —
CVE-2022-38166 HIGH 7.5 f-secure elements_endpoint_protection In F-Secure Endpoint Protection for Windows and macOS before channel with Capricorn database 2022-11-22_07, the aerdl.dll unpacker handler crashes. This can lead to a scanning engine crash, triggerable remotely by an attacker for denial of service. 0.7% —
CVE-2022-38046 HIGH 7.5 microsoft windows_10 Web Account Manager Information Disclosure Vulnerability 1.9% —
CVE-2022-38041 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 2.2% —
CVE-2022-38036 HIGH 7.5 microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability 2.2% —
CVE-2022-38013 HIGH 7.5 fedoraproject fedora .NET Core and Visual Studio Denial of Service Vulnerability 4.0% —
CVE-2022-37978 HIGH 7.5 microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass 1.5% —
CVE-2022-37972 HIGH 7.5 microsoft endpoint_configuration_manager Microsoft Endpoint Configuration Manager Spoofing Vulnerability 1.9% —
CVE-2022-37866 HIGH 7.5 apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" 1.7% —
CVE-2022-36946 HIGH 7.5 debian debian_linux nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nf_queue verdict with a one-byte nfta_payload attribute, an skb_pull can encounter a neg 7.6% —
CVE-2022-36374 HIGH 7.5 intel aptio_v_uefi_firmware_integrator_tools Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access. 0.2% —
CVE-2022-36127 HIGH 7.5 apache skywalking_nodejs_agent A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection. 1.8% —
CVE-2022-36125 HIGH 7.5 apache avro It is possible to crash (panic) an application by providing a corrupted data to be read. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro version 0.14.0 which addr 1.5% —
CVE-2022-36124 HIGH 7.5 apache avro It is possible for a Reader to consume memory beyond the allowed constraints and thus lead to out of memory on the system. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apa 1.4% —
CVE-2022-35838 HIGH 7.5 microsoft windows_11 HTTP V3 Denial of Service Vulnerability 2.7% —
CVE-2022-35833 HIGH 7.5 microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability 3.0% —
CVE-2022-35796 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.3% —
CVE-2022-35769 HIGH 7.5 microsoft windows_10 Windows Point-to-Point Protocol (PPP) Denial of Service Vulnerability 2.4% —
CVE-2022-35748 HIGH 7.5 microsoft windows_server_2012 HTTP.sys Denial of Service Vulnerability 47.2% —
CVE-2022-35742 HIGH 7.5 microsoft 365_apps Microsoft Outlook Denial of Service Vulnerability 22.4% —
CVE-2022-35724 HIGH 7.5 apache avro It is possible to provide data to be read that leads the reader to loop in cycles endlessly, consuming CPU. This issue affects Rust applications using Apache Avro Rust SDK prior to 0.14.0 (previously known as avro-rs). Users should update to apache-avro versio 1.7% —
CVE-2022-35715 HIGH 7.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231 1.0% —
CVE-2022-35639 HIGH 7.5 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cause the server to become unresponsive. IBM X-Force ID: 230932. 1.0% —
CVE-2022-35272 HIGH 7.5 f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1 and 16.1.x before 16.1.3.1, when source-port preserve-strict is configured on an HTTP Message Routing Framework (MRF) virtual server, undisclosed traffic may cause the Traffic Management Microkernel (TMM) to produce a 0.5% —