57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21850 | HIGH 8.8 | microsoft windows_10 Remote Desktop Client Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-21840 | HIGH 8.8 | microsoft excel Microsoft Office Remote Code Execution Vulnerability | 3.1% | — |
| CVE-2022-2162 | HIGH 8.8 | fedoraproject fedora Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page. | 1.2% | — |
| CVE-2022-20961 | HIGH 8.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. This vul | 0.4% | — |
| CVE-2022-20921 | HIGH 8.8 | cisco aci_multi-site_orchestrator A vulnerability in the API implementation of Cisco ACI Multi-Site Orchestrator (MSO) could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to improper authorization on specific APIs. An attacker co | 1.2% | — |
| CVE-2022-20824 | HIGH 8.8 | cisco mds_9506_firmware A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected | 0.4% | — |
| CVE-2022-20759 | HIGH 8.8 | cisco adaptive_security_appliance_software A vulnerability in the web services interface for remote access VPN features of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, but unprivileged, remote attacker to elevate privil | 29.2% | — |
| CVE-2022-20650 | HIGH 8.8 | cisco nx-os A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation of user supplied data that is sent to the | 14.5% | — |
| CVE-2022-1316 | HIGH 8.8 | zerotier zerotierone Incorrect Permission Assignment for Critical Resource in GitHub repository zerotier/zerotierone prior to 1.8.8. Local Privilege Escalation | 0.4% | — |
| CVE-2022-1043 | HIGH 8.8 | linux linux_kernel A flaw was found in the Linux kernel’s io_uring implementation. This flaw allows an attacker with a local account to corrupt system memory, crash the system or escalate privileges. | 3.8% | — |
| CVE-2022-1030 | HIGH 8.8 | okta advanced_server_access Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a valid target host wh | 1.5% | — |
| CVE-2022-0972 | HIGH 8.8 | google chrome Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | 0.8% | — |
| CVE-2022-0971 | HIGH 8.8 | google chrome Use after free in Blink Layout in Google Chrome on Android prior to 99.0.4844.74 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | 1.2% | — |
| CVE-2022-0805 | HIGH 8.8 | google chrome Use after free in Browser Switcher in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via user interaction. | 0.9% | — |
| CVE-2022-0799 | HIGH 8.8 | google chrome Insufficient policy enforcement in Installer in Google Chrome on Windows prior to 99.0.4844.51 allowed a remote attacker to perform local privilege escalation via a crafted offline installer file. | 1.0% | — |
| CVE-2022-0798 | HIGH 8.8 | google chrome Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | 0.7% | — |
| CVE-2022-0797 | HIGH 8.8 | google chrome Out of bounds memory access in Mojo in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. | 1.7% | — |
| CVE-2022-0796 | HIGH 8.8 | google chrome Use after free in Media in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1.0% | — |
| CVE-2022-0791 | HIGH 8.8 | google chrome Use after free in Omnibox in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via user interactions. | 0.9% | — |
| CVE-2022-0435 | HIGH 8.8 | fedoraproject fedora A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system | 68.0% | — |
| CVE-2021-47670 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_ | 0.2% | — |
| CVE-2021-47668 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: dev: can_restart: fix use after free bug After calling netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the netif_r | 0.2% | — |
| CVE-2021-47520 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: pch_can: pch_can_rx_normal: fix use after free After calling netif_receive_skb(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is dereferenced j | 0.3% | — |
| CVE-2021-47450 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Fix host stage-2 PGD refcount The KVM page-table library refcounts the pages of concatenated stage-2 PGDs individually. However, when running KVM in protected mode, the host's st | 0.2% | — |
| CVE-2021-47390 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Fix stack-out-of-bounds memory access from ioapic_write_indirect() KASAN reports the following issue: BUG: KASAN: stack-out-of-bounds in kvm_make_vcpus_request_mask+0x174/0x440 [ | 0.3% | — |