57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3587 | MED 6.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user. The vulnerability exists because the web-based management in | 0.6% | — |
| CVE-2019-6663 | MED 5.5 | f5 big-ip_access_policy_manager The BIG-IP 15.0.0-15.0.1, 14.0.0-14.1.2.2, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5.1, BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1 configuration utility is vulnerable to Anti DNS Pinning (DNS Rebinding) at | 0.6% | — |
| CVE-2014-3321 | MED 5.7 | cisco asr_9000_rsp440_router Cisco IOS XR 4.3.4 and earlier on ASR 9000 devices, when bridge-group virtual interface (BVI) routing is enabled, allows remote attackers to cause a denial of service (chip and card hangs) via a series of crafted MPLS packets, aka Bug ID CSCuo91149. | 0.6% | — |
| CVE-2014-3145 | MED 4.9 | canonical ubuntu_linux The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and syste | 0.6% | — |
| CVE-2014-2115 | MED 6.8 | cisco emergency_responder Multiple cross-site request forgery (CSRF) vulnerabilities in CERUserServlet pages in Cisco Emergency Responder (ER) 8.6 and earlier allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCun24250. | 0.6% | — |
| CVE-2014-1446 | LOW 1.9 | linux linux_kernel The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an | 0.6% | — |
| CVE-2026-65813 | MED 6.5 | microsoft exchange_server Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-26035 | CRIT 9.8 | fortinet fortiweb An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthentica | 0.7% | — |
| CVE-2026-24209 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause a path traversal issue. A successful exploit of this vulnerability might lead to denial of service. | 0.7% | — |
| CVE-2025-66200 | MED 5.4 | apache http_server mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the RequestHeader directive in htaccess can cause some CGI scripts to run under an unexpected userid. This issue affects Apache HTTP Server: fro | 0.7% | — |
| CVE-2025-53804 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-53803 | MED 5.5 | microsoft windows_10_1507 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-30386 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-21402 | HIGH 7.8 | microsoft office Microsoft Office OneNote Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43883 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: usb: vhci-hcd: Do not drop references before new references are gained At a few places the driver carries stale pointers to references that can still be used. Make sure that does not happen. | 0.7% | — |
| CVE-2024-43503 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26755 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: md: Don't suspend the array for interrupted reshape md_start_sync() will suspend the array if there are spares that can be added or removed from conf, however, if reshape is still in progres | 0.7% | — |
| CVE-2024-26245 | HIGH 7.8 | microsoft windows_10_1507 Windows SMB Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35323 | HIGH 7.8 | microsoft windows_11_21h2 Windows OLE Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35313 | HIGH 7.8 | microsoft windows_10_1507 Windows Online Certificate Status Protocol (OCSP) SnapIn Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23377 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-30611 | MED 5.4 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using some fields of the form in the portal UI to inject | 0.7% | — |
| CVE-2022-26788 | HIGH 7.8 | microsoft powershell PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-23764 | HIGH 8.8 | teruten webcube The vulnerability causing from insufficient verification procedures for downloaded files during WebCube update. Remote attackers can bypass this verification logic to update both digitally signed and unauthorized files, enabling remote code execution. | 0.7% | — |
| CVE-2021-0208 | HIGH 8.8 | juniper junos An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD | 0.7% | — |