58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-38021 | HIGH 7.0 | microsoft windows_10 Connected User Experiences and Telemetry Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-38014 | HIGH 7.0 | microsoft azure_iot_edge_for_linux Windows Subsystem for Linux (WSL2) Kernel Elevation of Privilege Vulnerability | 0.3% | — |
| CVE-2022-34725 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 5.4% | — |
| CVE-2022-33877 | HIGH 7.0 | fortinet forticlient An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConverter (Windows) versions 6.2.0 through 6.2.1, 7.0.0 and all versions of 6.0.0 may allow a local authenticated att | 0.2% | — |
| CVE-2022-33646 | HIGH 7.0 | microsoft azure_batch Azure Batch Node Agent Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-33644 | HIGH 7.0 | microsoft windows_10 Xbox Live Save Service Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-30298 | HIGH 7.0 | fortinet fortisoar An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify system files (via another, unrelated and hypothetical exploit) to execute arbitrary Python commands as root. | 0.2% | — |
| CVE-2022-3028 | HIGH 7.0 | debian debian_linux A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak | 0.2% | — |
| CVE-2022-30224 | HIGH 7.0 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-30202 | HIGH 7.0 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2022-30151 | HIGH 7.0 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-2961 | HIGH 7.0 | fedoraproject fedora A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate th | 0.3% | — |
| CVE-2022-2959 | HIGH 7.0 | linux linux_kernel A race condition was found in the Linux kernel's watch queue due to a missing lock in pipe_resize_ring(). The specific flaw exists within the handling of pipe buffers. The issue results from the lack of proper locking when performing operations on an object. T | 0.4% | — |
| CVE-2022-29582 | HIGH 7.0 | debian debian_linux In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due to a race condition in io_uring timeouts. This can be triggered by a local user who has no access to any user namespace; however, the race condition perhaps can only be exploited infrequ | 0.8% | — |
| CVE-2022-29151 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29150 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29142 | HIGH 7.0 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 5.1% | — |
| CVE-2022-29138 | HIGH 7.0 | microsoft windows_server Windows Clustered Shared Volume Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29135 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-29126 | HIGH 7.0 | microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-29125 | HIGH 7.0 | microsoft windows_10 Windows Push Notifications Apps Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-29106 | HIGH 7.0 | microsoft windows_10 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-28796 | HIGH 7.0 | fedoraproject fedora jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | 0.3% | — |
| CVE-2022-26939 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-26938 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.7% | — |