CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,540
Total CVEs
1,540
CISA KEV
1540
Critical & High
Mar 11, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2022-32894 | High | AppleiOS and macOS | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges. | Aug 18, 2022 | KEV |
| CVE-2022-32893 | High | AppleiOS and macOS | Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content. | Aug 18, 2022 | KEV |
| CVE-2022-2856 | High | GoogleChromium Intents | Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Aug 18, 2022 | KEV |
| CVE-2022-26923 | High | MicrosoftActive Directory | An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM. | Aug 18, 2022 | KEV |
| CVE-2022-21971 | High | MicrosoftWindows | Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution. | Aug 18, 2022 | KEV |
| CVE-2017-15944 | High | Palo Alto NetworksPAN-OS | Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained. | Aug 18, 2022 | KEV |
| CVE-2022-22536 | High | SAPMultiple Products | SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches. | Aug 18, 2022 | KEV |
| CVE-2022-27925 | High | SynacorZimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution. | Aug 11, 2022 | KEV |
| CVE-2022-37042 | High | SynacorZimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution. | Aug 11, 2022 | KEV |
| CVE-2022-34713 | High | MicrosoftWindows | A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application. | Aug 9, 2022 | KEV |
| CVE-2022-30333 | High | RARLABUnRAR | RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation. | Aug 9, 2022 | KEV |
| CVE-2022-27924 | High | SynacorZimbra Collaboration Suite (ZCS) | Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries. | Aug 4, 2022 | KEV |
| CVE-2022-26138 | High | AtlassianConfluence | Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group. | Jul 29, 2022 | KEV |
| CVE-2022-22047 | High | MicrosoftWindows | Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges. | Jul 12, 2022 | KEV |
| CVE-2022-26925 | High | MicrosoftWindows | Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. | Jul 1, 2022 | KEV |
| CVE-2019-8605 | High | AppleMultiple Products | A use-after-free vulnerability in Apple iOS, macOS, tvOS, and watchOS could allow a malicious application to execute code with system privileges. | Jun 27, 2022 | KEV |
| CVE-2018-4344 | High | AppleMultiple Products | Apple iOS, macOS, tvOS, and watchOS contain a memory corruption vulnerability which can allow for code execution. | Jun 27, 2022 | KEV |
| CVE-2022-29499 | High | MitelMiVoice Connect | The Service Appliance component in Mitel MiVoice Connect allows remote code execution due to incorrect data validation. | Jun 27, 2022 | KEV |
| CVE-2021-30533 | High | GoogleChromium PopupBlocker | Google Chromium PopupBlocker contains an insufficient policy enforcement vulnerability that allows a remote attacker to bypass navigation restrictions via a crafted iframe. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Jun 27, 2022 | KEV |
| CVE-2021-4034 | High | Red HatPolkit | The Red Hat polkit pkexec utility contains an out-of-bounds read and write vulnerability that allows for privilege escalation with administrative rights. | Jun 27, 2022 | KEV |