57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.490 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-37930 | HIGH 7.5 | fortinet fortios Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted | 0.6% | — |
| CVE-2023-36883 | MED 4.3 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 0.6% | — |
| CVE-2023-22404 | MED 6.5 | juniper junos An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on SRX series and MX with SPC3 allows an authenticated, network-based attacker to cause a Denial of Service (DoS). iked will crash and restart | 0.6% | — |
| CVE-2022-31674 | MED 4.3 | vmware vrealize_operations VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure. | 0.6% | — |
| CVE-2019-15213 | MED 4.6 | linux linux_kernel An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. | 0.6% | — |
| CVE-2019-0026 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on adm | 0.6% | — |
| CVE-2018-0415 | MED 6.8 | cisco wap121_firmware A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjace | 0.6% | — |
| CVE-2014-8480 | MED 4.9 | linux linux_kernel The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer derefere | 0.6% | — |
| CVE-2026-8655 | CRIT 9.8 | citrix netscaler_application_delivery_controller Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScal | 0.6% | — |
| CVE-2026-81963 | HIGH 7.8 | microsoft windows_11_23h2 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. | 0.6% | |
| CVE-2026-68525 | CRIT 9.1 | apache tomcat Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0. | 0.6% | — |
| CVE-2026-57211 | MED 6.5 | broadcom rabbitmq_server RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple | 0.6% | — |
| CVE-2025-30377 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-29834 | HIGH 7.5 | microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-21795 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is | 0.6% | — |
| CVE-2025-21336 | MED 5.6 | microsoft windows_10_1507 Windows Cryptographic Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-42108 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: rswitch: Avoid use-after-free in rswitch_poll() The use-after-free is actually in rswitch_tx_free(), which is inlined in rswitch_poll(). Since `skb` and `gq->skbs[gq->dirty]` are in fac | 0.6% | — |
| CVE-2024-41079 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: always initialize cqe.result The spec doesn't mandate that the first two double words (aka results) for the command queue entry need to be set to 0 when they are not used (not specifi | 0.6% | — |
| CVE-2024-38151 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38013 | MED 6.7 | microsoft windows_10_1507 Microsoft Windows Server Backup Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-35865 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. | 0.6% | — |
| CVE-2024-29733 | LOW 2.7 | apache apache-airflow-providers-ftp Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing context=ssl.crea | 0.6% | — |
| CVE-2024-26769 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try to flush the nvmet_wq nested. Avoid this by deadlock by defer | 0.6% | — |
| CVE-2023-37453 | MED 4.6 | linux linux_kernel An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c. | 0.6% | — |
| CVE-2023-33161 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.6% | — |