57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-0248 | LOW 3.3 | apache commons_fileupload The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. | 0.7% | — |
| CVE-2012-4001 | MED 5.0 | google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. | 0.7% | — |
| CVE-2024-38215 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38135 | HIGH 7.8 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38134 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-27439 | MED 6.5 | apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo | 0.7% | — |
| CVE-2023-35315 | HIGH 8.8 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28296 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21967 | HIGH 7.0 | microsoft windows_10 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-47478 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: isofs: Fix out of bound access for corrupted isofs image When isofs image is suitably corrupted isofs_read_inode() can read data beyond the end of buffer. Sanity-check the directory entry le | 0.7% | — |
| CVE-2021-29773 | MED 5.4 | ibm security_guardium IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865. | 0.7% | — |
| CVE-2020-5905 | MED 4.3 | f5 big-ip_access_policy_manager In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display. | 0.7% | — |
| CVE-2020-3199 | HIGH 8.8 | cisco ios Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker t | 0.7% | — |
| CVE-2026-50628 | CRIT 9.8 | apache cxf A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recomme | 0.7% | — |
| CVE-2026-49086 | MED 6.5 | apache camel Improper Input Validation, Unintended Proxy or Intermediary ('Confused Deputy') vulnerability in Apache Camel DAPR component. The camel-dapr Dapr Pub/Sub consumer (DaprPubSubConsumer) copied two fields from each inbound CloudEvent - its Pub/Sub component name | 0.7% | — |
| CVE-2025-37879 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read co | 0.7% | — |
| CVE-2024-43497 | HIGH 8.4 | microsoft deepspeed DeepSpeed Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-38203 | MED 6.2 | microsoft windows_10_1507 Windows Package Library Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-22234 | HIGH 7.4 | vmware spring_security In Spring Security, versions 6.1.x prior to 6.1.7 and versions 6.2.x prior to 6.2.2, an application is vulnerable to broken access control when it directly uses the AuthenticationTrustResolver.isFullyAuthenticated(Authentication) method. Specifically, an appl | 0.7% | — |
| CVE-2023-44253 | MED 5.0 | fortinet fortianalyzer An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allow | 0.7% | — |
| CVE-2023-36773 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-36772 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-36771 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-24513 | MED 6.5 | arista cloudeos On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are | 0.7% | — |
| CVE-2023-20200 | HIGH 7.7 | cisco firepower_4112_firmware A vulnerability in the Simple Network Management Protocol (SNMP) service of Cisco FXOS Software for Firepower 4100 Series and Firepower 9300 Security Appliances and of Cisco UCS 6300 Series Fabric Interconnects could allow an authenticated, remote attacker to | 0.7% | — |