58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.290 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-30167 | HIGH 7.8 | microsoft av1_video_extension AV1 Video Extension Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-30166 | HIGH 7.8 | microsoft windows_10 Local Security Authority Subsystem Service Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2022-30164 | HIGH 7.8 | microsoft windows_10 Kerberos AppContainer Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2022-30160 | HIGH 7.8 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 6.3% | — |
| CVE-2022-30147 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 4.5% | — |
| CVE-2022-30138 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-30135 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-30132 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-30131 | HIGH 7.8 | microsoft windows_server_2016 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-29968 | HIGH 7.8 | fedoraproject fedora An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private. | 1.1% | — |
| CVE-2022-2978 | HIGH 7.8 | debian debian_linux A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate | 0.2% | — |
| CVE-2022-2977 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux kernel implementation of proxied virtualized TPM devices. On a system where virtualized TPM devices are configured (this is not the default) a local attacker can create a use-after-free and create a situation where it may be possi | 0.2% | — |
| CVE-2022-2964 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. | 0.3% | — |
| CVE-2022-29594 | HIGH 7.8 | eginnovations eg_agent eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM. | 0.3% | — |
| CVE-2022-29583 | HIGH 7.8 | service_project service service_windows.go in the kardianos service package for Go omits quoting that is sometimes needed for execution of a Windows service executable from the intended directory. NOTE: this finding could not be reproduced by its original reporter or by others. | 0.3% | — |
| CVE-2022-29581 | HIGH 7.8 | canonical ubuntu_linux Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions prior to 5.18; version 4.14 and later versions. | 0.9% | — |
| CVE-2022-2938 | HIGH 7.8 | fedoraproject fedora A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects. | 0.3% | — |
| CVE-2022-29263 | HIGH 7.8 | f5 access_policy_manager_clients On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, as well as F5 BIG-IP APM Clients 7.x versions prior to 7.2.1.5, th | 0.2% | — |
| CVE-2022-29156 | HIGH 7.8 | linux linux_kernel drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. | 0.4% | — |
| CVE-2022-29149 | HIGH 7.8 | microsoft azure_automation_state_configuration Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-29148 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 2.8% | — |
| CVE-2022-29132 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-29119 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.2% | — |
| CVE-2022-29115 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-29113 | HIGH 7.8 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 0.4% | — |