58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.290 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24091 | HIGH 7.8 | adobe acrobat Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation | 4.1% | — |
| CVE-2022-23909 | HIGH 7.8 | gimmal sherpa_connector_service There is an unquoted service path in Sherpa Connector Service (SherpaConnectorService.exe) 2020.2.20328.2050. This might allow a local user to escalate privileges by creating a "C:\Program Files\Sherpa Software\Sherpa.exe" file. | 1.0% | — |
| CVE-2022-23766 | HIGH 7.8 | bigfile bigfileagent An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a gene | 0.6% | — |
| CVE-2022-23763 | HIGH 7.8 | douzone neors Origin validation error vulnerability in NeoRS’s ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access crafted web pages, causing damage such as malicious code infection | 0.3% | — |
| CVE-2022-23748 | HIGH 7.8 | audinate dante_application_library mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load mal | 9.1% | |
| CVE-2022-23742 | HIGH 7.8 | checkpoint endpoint_security Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpat | 4.2% | — |
| CVE-2022-23714 | HIGH 7.8 | elastic endpoint_security A local privilege escalation (LPE) issue was discovered in the ransomware canaries features of Elastic Endpoint Security for Windows, which could allow unprivileged users to elevate their privileges to those of the LocalSystem account. | 0.2% | — |
| CVE-2022-23440 | HIGH 7.8 | fortinet fortiedr A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow a local attacker to disable and uninstall the collectors from the end-points within the same deploy | 0.2% | — |
| CVE-2022-23301 | HIGH 7.8 | microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23300 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23299 | HIGH 7.8 | microsoft windows_10 Windows PDEV Elevation of Privilege Vulnerability | 7.6% | — |
| CVE-2022-23296 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-23295 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-23293 | HIGH 7.8 | microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-23291 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23290 | HIGH 7.8 | microsoft windows_10 Windows Inking COM Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23282 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 2.4% | — |
| CVE-2022-23276 | HIGH 7.8 | microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-23266 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-23222 | HIGH 7.8 | debian debian_linux kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. | 1.9% | — |
| CVE-2022-23205 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.6 (and earlier)and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 2.3% | — |
| CVE-2022-23200 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 22.1.1 (and earlier) and 18.4.3 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 3.0% | — |
| CVE-2022-23188 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by a buffer overflow vulnerability due to insecure handling of a crafted malicious file, potentially resulting in arbitrary code execution in the context of the current user. | 4.4% | — |
| CVE-2022-23187 | HIGH 7.8 | adobe illustrator Adobe Illustrator version 26.0.3 (and earlier) is affected by a buffer overflow vulnerability due to insecure handling of a crafted file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interacti | 4.3% | — |
| CVE-2022-23186 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 2.3% | — |