58.285 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.285 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37384 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.0% | — |
| CVE-2022-37381 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific | 1.0% | — |
| CVE-2022-37378 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.0% | — |
| CVE-2022-37377 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Editor 11.1.1.53537;. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file | 1.0% | — |
| CVE-2022-37173 | HIGH 7.8 | vim gvim An issue in the installer of gvim 9.0.0000 allows authenticated attackers to execute arbitrary code via a binary hijacking attack on C:\Program.exe. | 0.4% | — |
| CVE-2022-36336 | HIGH 7.8 | trendmicro apex_one A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically | 0.6% | — |
| CVE-2022-36123 | HIGH 7.8 | linux linux_kernel The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges. | 0.9% | — |
| CVE-2022-36122 | HIGH 7.8 | automox automox The Automox Agent before 40 on Windows incorrectly sets permissions on key files. | 0.2% | — |
| CVE-2022-35899 | HIGH 7.8 | asus aura_ready_game_software_development_kit There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file. | 0.9% | — |
| CVE-2022-35849 | HIGH 7.8 | fortinet fortiadc An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0 through 6.2.5 and 6.1.0 all versions may allow an authenticated attacker to exe | 0.5% | — |
| CVE-2022-35845 | HIGH 7.8 | fortinet fortitester Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitra | 1.1% | — |
| CVE-2022-35828 | HIGH 7.8 | microsoft defender_for_endpoint Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35820 | HIGH 7.8 | microsoft windows_10 Windows Bluetooth Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-35806 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-35803 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 23.8% | — |
| CVE-2022-35795 | HIGH 7.8 | microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-35792 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-35779 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-35773 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-35771 | HIGH 7.8 | microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-3577 | HIGH 7.8 | linux linux_kernel An out-of-bounds memory write flaw was found in the Linux kernel’s Kid-friendly Wired Controller driver. This flaw allows a local user to crash or potentially escalate their privileges on the system. It is in bigben_probe of drivers/hid/hid-bigbenff.c. The rea | 0.3% | — |
| CVE-2022-35768 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-35765 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35764 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-35763 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0.5% | — |