IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-0132 MED 6.5 google chrome Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to force acceptance of a permission prompt via a crafted HTML page. (Chromium security severity: Medium) 0.5% —
CVE-2023-0007 MED 6.5 paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software on Panorama appliances enables an authenticated read-write administrator to store a JavaScript payload in the web interface that will execute in the context of another administrat 0.4% —
CVE-2023-0004 MED 6.5 fedoraproject fedora A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity 1.1% —
CVE-2023-0003 MED 6.5 fedoraproject fedora A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. 1.3% —
CVE-2022-47938 MED 6.5 linux linux_kernel An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2misc.c has an out-of-bounds read and OOPS for SMB2_TREE_CONNECT. 60.0% —
CVE-2022-46651 MED 6.5 apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection re 1.2% —
CVE-2022-45861 MED 6.5 fortinet fortios An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2 0.8% —
CVE-2022-45857 MED 6.5 fortinet fortimanager An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to access a FortiGate without a password via newly created VDOMs after the super_admin account is deleted. 0.3% —
CVE-2022-45449 MED 6.5 acronis cyber_protect Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 30984. 0.4% —
CVE-2022-44707 MED 6.5 microsoft windows_10 Windows Kernel Denial of Service Vulnerability 2.5% —
CVE-2022-44684 MED 6.5 microsoft windows_10_20h2 Windows Local Session Manager (LSM) Denial of Service Vulnerability 1.5% —
CVE-2022-44679 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 0.5% —
CVE-2022-44644 MED 6.5 apache linkis In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the 1.2% —
CVE-2022-43869 MED 6.5 ibm elastic_storage_system IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string a 1.0% —
CVE-2022-43516 MED 6.5 microsoft windows_firewall A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) 0.9% —
CVE-2022-42474 MED 6.5 fortinet fortios A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.12, FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiSwitchManager version 7.2.0 through 7.2.1 and 0.6% —
CVE-2022-42343 MED 6.5 adobe campaign Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitr 1.4% —
CVE-2022-4187 MED 6.5 google chrome Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 108.0.5359.71 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium) 0.6% —
CVE-2022-41813 MED 6.5 f5 big-ip_advanced_firewall_manager In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate. 0.6% —
CVE-2022-41770 MED 6.5 f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource ut 0.6% —
CVE-2022-41553 MED 6.5 hitachi infrastructure_analytics_advisor Insertion of Sensitive Information into Temporary File vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Analytics probe component), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer probe component) allows local users to gain 0.2% —
CVE-2022-41294 MED 6.5 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross origin resource sharing using the bot api. IBM X-Force ID: 236807. 0.3% —
CVE-2022-41291 MED 6.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 236699. 0.4% —
CVE-2022-41122 MED 6.5 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.6% —
CVE-2022-41097 MED 6.5 microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Information Disclosure Vulnerability 1.6% —