IT
57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.490 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2023-37930 HIGH 7.5 fortinet fortios Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt memory potentially leading to code or commands execution via specifically crafted 0.6%
CVE-2023-36883 MED 4.3 microsoft edge Microsoft Edge for iOS Spoofing Vulnerability 0.6%
CVE-2023-22404 MED 6.5 juniper junos An Out-of-bounds Write vulnerability in the Internet Key Exchange Protocol daemon (iked) of Juniper Networks Junos OS on SRX series and MX with SPC3 allows an authenticated, network-based attacker to cause a Denial of Service (DoS). iked will crash and restart 0.6%
CVE-2022-31674 MED 4.3 vmware vrealize_operations VMware vRealize Operations contains an information disclosure vulnerability. A low-privileged malicious actor with network access can access log files that lead to information disclosure. 0.6%
CVE-2019-15213 MED 4.6 linux linux_kernel An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. 0.6%
CVE-2019-0026 MED 5.4 juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Zone configuration of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on adm 0.6%
CVE-2018-0415 MED 6.8 cisco wap121_firmware A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Series Wireless Access Points could allow an authenticated, adjace 0.6%
CVE-2014-8480 MED 4.9 linux linux_kernel The instruction decoder in arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel before 3.18-rc2 lacks intended decoder-table flags for certain RIP-relative instructions, which allows guest OS users to cause a denial of service (NULL pointer derefere 0.6%
CVE-2026-8655 CRIT 9.8 citrix netscaler_application_delivery_controller Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScal 0.6%
CVE-2026-81963 HIGH 7.8 microsoft windows_11_23h2 Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2026-68525 CRIT 9.1 apache tomcat Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0. 0.6%
CVE-2026-57211 MED 6.5 broadcom rabbitmq_server RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm_static can pass URL-encoded backslashes to erl_prim_loader:read_file_info before path validation when multiple 0.6%
CVE-2025-30377 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-29834 HIGH 7.5 microsoft edge_chromium Out-of-bounds read in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2025-21795 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: fix hang in nfsd4_shutdown_callback If nfs4_client is in courtesy state then there is no point to send the callback. This causes nfsd4_shutdown_callback to hang since cl_cb_inflight is 0.6%
CVE-2025-21336 MED 5.6 microsoft windows_10_1507 Windows Cryptographic Information Disclosure Vulnerability 0.6%
CVE-2024-42108 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: rswitch: Avoid use-after-free in rswitch_poll() The use-after-free is actually in rswitch_tx_free(), which is inlined in rswitch_poll(). Since `skb` and `gq->skbs[gq->dirty]` are in fac 0.6%
CVE-2024-41079 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: always initialize cqe.result The spec doesn't mandate that the first two double words (aka results) for the command queue entry need to be set to 0 when they are not used (not specifi 0.6%
CVE-2024-38151 MED 5.5 microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability 0.6%
CVE-2024-38013 MED 6.7 microsoft windows_10_1507 Microsoft Windows Server Backup Elevation of Privilege Vulnerability 0.6%
CVE-2024-35865 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. 0.6%
CVE-2024-29733 LOW 2.7 apache apache-airflow-providers-ftp Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing context=ssl.crea 0.6%
CVE-2024-26769 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid deadlock on delete association path When deleting an association the shutdown path is deadlocking because we try to flush the nvmet_wq nested. Avoid this by deadlock by defer 0.6%
CVE-2023-37453 MED 4.6 linux linux_kernel An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c. 0.6%
CVE-2023-33161 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.6%