56.793 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync
CVE Tracker
56.793 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-39344 | CRIT 9.8 | microsoft azure_rtos_usbx Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memo | 2.0% | — |
| CVE-2022-39198 | CRIT 9.8 | apache dubbo A deserialization vulnerability existed in dubbo hessian-lite 3.2.12 and its earlier versions, which could lead to malicious code execution. This issue affects Apache Dubbo 2.7.x version 2.7.17 and prior versions; Apache Dubbo 3.0.x version 3.0.11 and prior ve | 2.6% | — |
| CVE-2022-39135 | CRIT 9.8 | apache calcite Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity references in their configuration, making them vulnerable to a potential XML External Entity (XXE) attack. Therefor | 2.0% | — |
| CVE-2022-38651 | CRIT 9.8 | vmware hyperic_server A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects pro | 0.8% | — |
| CVE-2022-38649 | CRIT 9.8 | apache airflow Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airflow Pinot Provider, Apache Airflow allows an attacker to control commands executed in the task execution context, without write access to DAG | 3.2% | — |
| CVE-2022-38221 | CRIT 9.8 | the_isle_evrima_project the_isle_evrima A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code. | 1.8% | — |
| CVE-2022-38054 | CRIT 9.8 | apache airflow In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation. | 1.9% | — |
| CVE-2022-37021 | CRIT 9.8 | apache geode Apache Geode versions up to 1.12.5, 1.13.4 and 1.14.0 are vulnerable to a deserialization of untrusted data flaw when using JMX over RMI on Java 8. Any user still on Java 8 who wishes to protect against deserialization attacks involving JMX or RMI should upgra | 2.8% | — |
| CVE-2022-36947 | CRIT 9.8 | faststone image_viewer Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow. | 2.8% | — |
| CVE-2022-36536 | CRIT 9.8 | syncovery syncovery An issue in the component post_applogin.php of Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below allows attackers to escalate privileges via creating crafted session tokens. | 4.0% | — |
| CVE-2022-35744 | CRIT 9.8 | microsoft windows_10_1507 Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability | 2.0% | — |
| CVE-2022-35741 | CRIT 9.8 | apache cloudstack Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entity (XXE) injection. This plugin is not enabled by default and the attacker would require that this plugin be ena | 7.9% | — |
| CVE-2022-35280 | CRIT 9.8 | ibm robotic_process_automation_for_cloud_pak IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 230634. | 0.8% | — |
| CVE-2022-34916 | CRIT 9.8 | apache flume Apache Flume versions 1.4.0 through 1.10.0 are vulnerable to a remote code execution (RCE) attack when a configuration uses a JMS Source with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JN | 2.8% | — |
| CVE-2022-34722 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2022-34721 | CRIT 9.8 | microsoft windows_10 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability | 78.5% | — |
| CVE-2022-34718 | CRIT 9.8 | microsoft windows_10 Windows TCP/IP Remote Code Execution Vulnerability | 46.6% | — |
| CVE-2022-34715 | CRIT 9.8 | microsoft windows_server_2022 Windows Network File System Remote Code Execution Vulnerability | 80.4% | — |
| CVE-2022-33980 | CRIT 9.8 | apache commons_configuration Apache Commons Configuration performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.configurat | 42.9% | — |
| CVE-2022-33874 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote atta | 2.9% | — |
| CVE-2022-33872 | CRIT 9.8 | fortinet fortitester An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote a | 2.9% | — |
| CVE-2022-33127 | CRIT 9.8 | diffy_project diffy The function that calls the diff tool in Diffy 3.4.1 does not properly handle double quotes in a filename when run in a windows environment. This allows attackers to execute arbitrary commands via a crafted string. | 1.7% | — |
| CVE-2022-32533 | CRIT 9.8 | apache jetspeed Apache Jetspeed-2 does not sufficiently filter untrusted user input by default leading to a number of issues including XSS, CSRF, XXE, and SSRF. Setting the configuration option "xss.filter.post = true" may mitigate these issues. NOTE: Apache Jetspeed is a dor | 3.9% | — |
| CVE-2022-32532 | CRIT 9.8 | apache shiro Apache Shiro before 1.9.1, A RegexRequestMatcher can be misconfigured to be bypassed on some servlet containers. Applications using RegExPatternMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass. | 27.2% | — |
| CVE-2022-3229 | CRIT 9.8 | unifiedremote unified_remote Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this no | 66.4% | — |