57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-34493 | MED 6.7 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-15917 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c. | 0.6% | — |
| CVE-2015-0239 | MED 4.4 | canonical ubuntu_linux The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16 | 0.6% | — |
| CVE-2014-8031 | MED 6.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456. | 0.6% | — |
| CVE-2014-7996 | MED 6.8 | cisco unified_computing_system Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuq45477. | 0.6% | — |
| CVE-2012-3908 | MED 6.8 | cisco identity_services_engine Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hi | 0.6% | — |
| CVE-2026-58279 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-50169 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2025-47995 | MED 6.5 | microsoft azure_machine_learning Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2024-36476 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move the declaration of the 'ib_sge list' variable outside the 'always_invalidate' block to ensure it remains accessible for use throughout the | 0.6% | — |
| CVE-2024-27181 | HIGH 8.8 | apache linkis In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue. | 0.6% | — |
| CVE-2024-26760 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: pscsi: Fix bio_put() for error case As of commit 066ff571011d ("block: turn bio_kmalloc into a simple kmalloc wrapper"), a bio allocated by bio_kmalloc() must be freed by bio_u | 0.6% | — |
| CVE-2024-20268 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the de | 0.6% | — |
| CVE-2023-32041 | MED 5.5 | microsoft windows_10_1607 Windows Update Orchestrator Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-22417 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In an IPsec VPN environment, a memory lea | 0.6% | — |
| CVE-2023-22413 | HIGH 7.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the IPsec library of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). On all MX platforms with MS-MPC or MS-MIC card, when spec | 0.6% | — |
| CVE-2023-22403 | HIGH 7.5 | juniper junos An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). On QFX10K Series, Inter-Chassis Co | 0.6% | — |
| CVE-2023-20133 | MED 5.4 | cisco webex_meetings A vulnerability in the web interface of Cisco Webex Meetings could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because of insufficient validation of | 0.6% | — |
| CVE-2022-29060 | HIGH 8.1 | fortinet fortiddos A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device. | 0.6% | — |
| CVE-2022-23438 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) | 0.6% | — |
| CVE-2022-23171 | MED 5.9 | atlasvpn atlasvpn AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed. | 0.6% | — |
| CVE-2022-22186 | HIGH 7.2 | juniper junos Due to an Improper Initialization vulnerability in Juniper Networks Junos OS on EX4650 devices, packets received on the management interface (em0) but not destined to the device, may be improperly forwarded to an egress interface, instead of being discarded. S | 0.6% | — |
| CVE-2021-3491 | HIGH 7.8 | canonical ubuntu_linux The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading to ar | 0.6% | — |
| CVE-2019-19227 | MED 5.5 | linux linux_kernel In the AppleTalk subsystem in the Linux kernel before 5.1, there is a potential NULL pointer dereference because register_snap_client may return NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c, as demonstrated by unreg | 0.6% | — |
| CVE-2013-0311 | MED 6.5 | linux linux_kernel The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges. | 0.6% | — |