58.360 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.360 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30152 | HIGH 7.5 | microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.8% | — |
| CVE-2022-30150 | HIGH 7.5 | microsoft windows_10 Windows Defender Remote Credential Guard Elevation of Privilege Vulnerability | 3.4% | — |
| CVE-2022-30149 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-30146 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-30145 | HIGH 7.5 | microsoft windows_10 Windows Encrypting File System (EFS) Remote Code Execution Vulnerability | 2.1% | — |
| CVE-2022-30144 | HIGH 7.5 | microsoft windows_10 Windows Bluetooth Service Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-30143 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-30142 | HIGH 7.5 | microsoft windows_10 Windows File History Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30140 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Discovery Service Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-30139 | HIGH 7.5 | microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-29885 | HIGH 7.5 | apache tomcat The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the | 73.5% | — |
| CVE-2022-29804 | HIGH 7.5 | golang go Incorrect conversion of certain invalid paths to valid, absolute paths in Clean in path/filepath before Go 1.17.11 and Go 1.18.3 on Windows allows potential directory traversal attack. | 2.1% | — |
| CVE-2022-29491 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP LTM, Advanced WAF, ASM, or APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, 14.1.x versions prior to 14.1.4.6, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a virtual server is configured with HTTP, TCP on one side (c | 0.9% | — |
| CVE-2022-29404 | HIGH 7.5 | apache http_server In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. | 6.2% | — |
| CVE-2022-29369 | HIGH 7.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation via njs_lvlhsh_bucket_find at njs_lvlhsh.c. | 1.2% | — |
| CVE-2022-29266 | HIGH 7.5 | apache apisix In APache APISIX before 3.13.1, the jwt-auth plugin has a security issue that leaks the user's secret key because the error message returned from the dependency lua-resty-jwt contains sensitive information. | 8.1% | — |
| CVE-2022-29265 | HIGH 7.5 | apache nifi Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content Viewer service attempts to resolve XML External Entity references when viewing formatted XML files. The followi | 2.6% | — |
| CVE-2022-29158 | HIGH 7.5 | apache ofbiz Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599 | 2.0% | — |
| CVE-2022-29145 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5.1% | — |
| CVE-2022-29144 | HIGH 7.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-29143 | HIGH 7.5 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2022-29117 | HIGH 7.5 | fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability | 5.0% | — |
| CVE-2022-29055 | HIGH 7.5 | fortinet fortios A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProxy version 7.0.0 through 7.0.4, 2.0.0 through 2.0.9, 1.2.x allows a remote unauthenticated or authenticated atta | 1.0% | — |
| CVE-2022-28716 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page o | 0.8% | — |
| CVE-2022-28705 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, on platforms with an ePVA and the pva.fwdaccel BigDB variable enabled, undisclosed requests to a virtual | 0.9% | — |