IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-35891 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: phy: micrel: Fix potential null pointer dereference In lan8814_get_sig_rx() and lan8814_get_sig_tx() ptp_parse_header() may return NULL as ptp_header due to abnormal packet type or corr 0.6%
CVE-2024-28777 HIGH 8.8 ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to unrestricted deserialization. This vulnerability allows users to execute arbitrary code, escalate privileges, or cause denial of service attacks by exploiting the un 0.6%
CVE-2024-26868 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfs: fix panic when nfs4_ff_layout_prepare_ds() fails We've been seeing the following panic in production BUG: kernel NULL pointer dereference, address: 0000000000000065 PGD 2f485f067 P4D 2 0.6%
CVE-2024-20528 LOW 3.8 cisco identity_services_engine A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affected device. To exploit this vulnerability, an attacker would need valid Super Admin 0.6%
CVE-2023-47704 MED 4.0 ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 contains plain text hard-coded credentials or other secrets in source code repository. IBM X-Force ID: 271220. 0.6%
CVE-2023-24921 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2023-24919 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2023-24891 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2023-24879 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2023-21573 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2023-21571 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2023-21570 MED 5.4 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2022-48692 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Set scmnd->result only when scmnd is not NULL This change fixes the following kernel NULL pointer dereference which is reproduced by blktests srp/007 occasionally. BUG: kernel NUL 0.6%
CVE-2022-40748 MED 5.4 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust 0.6%
CVE-2022-35721 MED 5.4 ibm jazz_for_service_management IBM Jazz for Service Management 1.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a 0.6%
CVE-2022-29147 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.6%
CVE-2022-22247 HIGH 7.5 juniper junos_os_evolved An Improper Input Validation vulnerability in ingress TCP segment processing of Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker to send a crafted TCP segment to the device, triggering a kernel panic, leading to a Denial of Ser 0.6%
CVE-2018-15490 HIGH 7.1 expressvpn expressvpn An issue was discovered in ExpressVPN on Windows. The Xvpnd.exe process (which runs as a service with SYSTEM privileges) listens on TCP port 2015, which is used as an RPC interface for communication with the client side of the ExpressVPN application. A JSON-RP 0.6%
CVE-2012-4072 MED 4.3 cisco unified_computing_system The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka 0.6%
CVE-2026-78446 MED 5.3 microsoft windows_10_1607 Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. 0.6%
CVE-2025-49696 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2024-56662 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] B 0.6%
CVE-2024-38086 MED 6.4 microsoft azure_kinect_software_development_kit Azure Kinect SDK Remote Code Execution Vulnerability 0.6%
CVE-2023-36719 HIGH 7.8 microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability 0.6%
CVE-2023-36408 HIGH 7.8 microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability 0.6%