58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-0132 | MED 6.5 | google chrome Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium) | 0.5% | — |
| CVE-2023-0007 | MED 6.5 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrat | 0.4% | — |
| CVE-2023-0004 | MED 6.5 | fedoraproject fedora A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity | 1.1% | — |
| CVE-2023-0003 | MED 6.5 | fedoraproject fedora A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. | 1.3% | — |
| CVE-2022-47938 | MED 6.5 | linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT. | 60.0% | — |
| CVE-2022-46651 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection re | 1.2% | — |
| CVE-2022-45861 | MED 6.5 | fortinet fortios An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2 | 0.8% | — |
| CVE-2022-45857 | MED 6.5 | fortinet fortimanager An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted. | 0.3% | — |
| CVE-2022-45449 | MED 6.5 | acronis cyber_protect Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. | 0.4% | — |
| CVE-2022-44707 | MED 6.5 | microsoft windows_10 Windows Kernel Denial of Service Vulnerability | 2.5% | — |
| CVE-2022-44684 | MED 6.5 | microsoft windows_10_20h2 Windows Local Session Manager (LSM) Denial of Service Vulnerability | 1.5% | — |
| CVE-2022-44679 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-44644 | MED 6.5 | apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the | 1.2% | — |
| CVE-2022-43869 | MED 6.5 | ibm elastic_storage_system IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string a | 1.0% | — |
| CVE-2022-43516 | MED 6.5 | microsoft windows_firewall A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) | 0.9% | — |
| CVE-2022-42474 | MED 6.5 | fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and | 0.6% | — |
| CVE-2022-42343 | MED 6.5 | adobe campaign Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitr | 1.4% | — |
| CVE-2022-4187 | MED 6.5 | google chrome Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) | 0.6% | — |
| CVE-2022-41813 | MED 6.5 | f5 big-ip_advanced_firewall_manager In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate. | 0.6% | — |
| CVE-2022-41770 | MED 6.5 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource ut | 0.6% | — |
| CVE-2022-41553 | MED 6.5 | hitachi infrastructure_analytics_advisor Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain | 0.2% | — |
| CVE-2022-41294 | MED 6.5 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. | 0.3% | — |
| CVE-2022-41291 | MED 6.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. | 0.4% | — |
| CVE-2022-41122 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.6% | — |
| CVE-2022-41097 | MED 6.5 | microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability | 1.6% | — |