IT
57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.613 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-0248 LOW 3.3 apache commons_fileupload The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. 0.7%
CVE-2012-4001 MED 5.0 google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. 0.7%
CVE-2024-38215 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.7%
CVE-2024-38135 HIGH 7.8 microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.7%
CVE-2024-38134 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 0.7%
CVE-2024-27439 MED 6.5 apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo 0.7%
CVE-2023-35315 HIGH 8.8 microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability 0.7%
CVE-2023-28296 HIGH 7.8 microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability 0.7%
CVE-2022-21967 HIGH 7.0 microsoft windows_10 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability 0.7%
CVE-2021-47478 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry le 0.7%
CVE-2021-29773 MED 5.4 ibm security_guardium IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865. 0.7%
CVE-2020-5905 MED 4.3 f5 big-ip_access_policy_manager In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display. 0.7%
CVE-2020-3199 HIGH 8.8 cisco ios Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker t 0.7%
CVE-2026-50628 CRIT 9.8 apache cxf A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recomme 0.7%
CVE-2026-49086 MED 6.5 apache camel Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name 0.7%
CVE-2025-37879 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read co 0.7%
CVE-2024-43497 HIGH 8.4 microsoft deepspeed DeepSpeed Remote Code Execution Vulnerability 0.7%
CVE-2024-38203 MED 6.2 microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability 0.7%
CVE-2024-22234 HIGH 7.4 vmware spring_security In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl 0.7%
CVE-2023-44253 MED 5.0 fortinet fortianalyzer An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allow 0.7%
CVE-2023-36773 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-36772 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-36771 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.7%
CVE-2023-24513 MED 6.5 arista cloudeos On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are 0.7%
CVE-2023-20200 HIGH 7.7 cisco firepower_4112_firmware A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to 0.7%