57.496 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.496 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36831 | HIGH 7.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading | 0.6% | — |
| CVE-2023-21820 | HIGH 7.4 | microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-20899 | HIGH 7.5 | vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. | 0.6% | — |
| CVE-2022-38007 | HIGH 7.8 | microsoft azure_arc Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-34352 | MED 6.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403. | 0.6% | — |
| CVE-2022-22753 | HIGH 7.1 | mozilla firefox A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other | 0.6% | — |
| CVE-2021-43207 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-32602 | MED 5.8 | fortinet fortiportal An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote a | 0.6% | — |
| CVE-2021-1135 | MED 4.6 | cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the | 0.6% | — |
| CVE-2019-19966 | MED 4.6 | debian debian_linux In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655. | 0.6% | — |
| CVE-2018-0163 | MED 6.5 | cisco ios A vulnerability in the 802.1x multiple-authentication (multi-auth) feature of Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass the authentication phase on an 802.1x multi-auth port. The vulnerability is due to a logic change error | 0.6% | — |
| CVE-2016-2082 | HIGH 8.8 | vmware vrealize_log_insight Cross-site request forgery (CSRF) vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.3.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 0.6% | — |
| CVE-2026-62822 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-24304 | CRIT 9.9 | microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-24281 | HIGH 7.4 | apache zookeeper Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It | 0.6% | — |
| CVE-2026-0279 | MED 6.1 | paloaltonetworks pan-os Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store | 0.6% | — |
| CVE-2025-29979 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-20127 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an aut | 0.6% | — |
| CVE-2024-45330 | HIGH 7.2 | fortinet fortianalyzer A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests. | 0.6% | — |
| CVE-2024-20271 | HIGH 8.6 | cisco business_access_points A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of | 0.6% | — |
| CVE-2023-44158 | HIGH 7.5 | acronis cyber_protect Sensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.6% | — |
| CVE-2022-47632 | MED 6.8 | razer synapse Razer Synapse before 3.7.0830.081906 allows privilege escalation due to an unsafe installation path, improper privilege management, and improper certificate validation. Attackers can place malicious DLLs into %PROGRAMDATA%\Razer\Synapse3\Service\bin if they do | 0.6% | — |
| CVE-2022-31734 | MED 6.1 | cisco ws-c2940-8tf-s_firmware Cisco Catalyst 2940 Series Switches provided by Cisco Systems, Inc. contain a reflected cross-site scripting vulnerability regarding error page generation. An arbitrary script may be executed on the web browser of the user who is using the product. The affecte | 0.6% | — |
| CVE-2021-46960 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Return correct error code from smb2_get_enc_key Avoid a warning if the error percolates back up: [440700.376476] CIFS VFS: \\otters.example.com crypt_message: Could not get encryption | 0.6% | — |
| CVE-2021-33774 | HIGH 7.0 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.6% | — |