58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22478 | MED 5.5 | ibm spectrum_protect_client IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886. | 0.2% | — |
| CVE-2022-22424 | MED 5.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow a local user to obtain sensitive information from the TLS key file due to incorrect file permissions. IBM X-Force ID: 223597. | 0.2% | — |
| CVE-2022-22423 | MED 5.5 | ibm common_cryptographic_architecture IBM Common Cryptographic Architecture (CCA 5.x MTM for 4767 and CCA 7.x MTM for 4769) could allow a local user to cause a denial of service due to improper input validation. IBM X-Force ID: 223596. | 0.3% | — |
| CVE-2022-22414 | MED 5.5 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.2 could allow a local user to obtain sensitive web service configuration credentials from system memory. IBM X-Force ID: 223026. | 0.2% | — |
| CVE-2022-22371 | MED 5.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 221195. | 0.3% | — |
| CVE-2022-22297 | MED 5.5 | fortinet fortirecorder_firmware An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.0 through 6.4.1, FortiWeb version 6.3.0 through 6.3.17, FortiWeb all versions 6.2, FortiWeb all versions 6.1, F | 0.2% | — |
| CVE-2022-22240 | MED 5.5 | juniper junos An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged | 0.2% | — |
| CVE-2022-22234 | MED 5.5 | juniper junos An Improper Preservation of Consistency Between Independent Representations of Shared State vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a locally authenticated attacker with low privileges to cause a Denial of Servic | 0.2% | — |
| CVE-2022-22233 | MED 5.5 | juniper junos An Unchecked Return Value to NULL Pointer Dereference vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). In Segment Ro | 0.2% | — |
| CVE-2022-22193 | MED 5.5 | juniper junos An Improper Handling of Unexpected Data Type vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Service (DoS). Continued executio | 0.2% | — |
| CVE-2022-22011 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-22002 | MED 5.5 | microsoft windows_10 Windows User Account Profile Picture Denial of Service Vulnerability | 1.3% | — |
| CVE-2022-21998 | MED 5.5 | microsoft windows_10 Windows Common Log File System Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-21985 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-21973 | MED 5.5 | microsoft windows_7 Windows Media Center Update Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-21964 | MED 5.5 | microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-21906 | MED 5.5 | microsoft windows_10 Windows Defender Application Control Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2022-21899 | MED 5.5 | microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | 1.4% | — |
| CVE-2022-21879 | MED 5.5 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-21877 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 2.9% | — |
| CVE-2022-21876 | MED 5.5 | microsoft windows_10 Win32k Information Disclosure Vulnerability | 1.3% | — |
| CVE-2022-21838 | MED 5.5 | microsoft windows_10 Windows Cleanup Manager Elevation of Privilege Vulnerability | 1.5% | — |
| CVE-2022-21815 | MED 5.5 | nvidia cloud_gaming_guest NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for private IOCTLs where a NULL pointer dereference in the kernel, created within user mode code, may lead to a denial of service in the form of a sy | 0.2% | — |
| CVE-2022-21793 | MED 5.5 | vmware i40en Insufficient control flow management in the Intel(R) Ethernet 500 Series Controller drivers for VMWare before version 1.11.4.0 and in the Intel(R) Ethernet 700 Series Controller drivers for VMWare before version 2.1.5.0 may allow an authenticated user to poten | 0.2% | — |
| CVE-2022-2153 | MED 5.5 | debian debian_linux A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to | 0.5% | — |