57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28352 | HIGH 7.4 | faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. By abusing the Insight UDP broadcast discovery system, an attacker-controlled artificial Student Console can connect to and attack a Teacher Console even after Enhanced Security Mode has been e | 0.7% | — |
| CVE-2021-1475 | MED 6.5 | cisco umbrella Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these v | 0.7% | — |
| CVE-2019-6658 | MED 4.3 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM 15.0.0-15.0.1, 14.0.0-14.1.2, 13.1.0-13.1.3.1, and 12.1.0-12.1.5, a vulnerability in the AFM configuration utility may allow any authenticated BIG-IP user to run an SQL injection attack. | 0.7% | — |
| CVE-2018-8356 | MED 5.5 | microsoft .net_core A security feature bypass vulnerability exists when Microsoft .NET Framework components do not correctly validate certificates, aka ".NET Framework Security Feature Bypass Vulnerability." This affects .NET Framework 4.7.2, Microsoft .NET Framework 3.0, Microso | 0.7% | — |
| CVE-2014-7997 | MED 6.1 | cisco ios The DHCP implementation in Cisco IOS on Aironet access points does not properly handle error conditions with short leases and unsuccessful lease-renewal attempts, which allows remote attackers to cause a denial of service (device restart) by triggering a trans | 0.7% | — |
| CVE-2012-3051 | MED 6.1 | cisco nexus_7000 Cisco NX-OS 5.2 and 6.1 on Nexus 7000 series switches allows remote attackers to cause a denial of service (process crash or packet loss) via a large number of ARP packets, aka Bug ID CSCtr44822. | 0.7% | — |
| CVE-2026-45481 | HIGH 7.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-42537 | CRIT 9.8 | apache ranger Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.7% | — |
| CVE-2025-61581 | HIGH 7.5 | apache traffic_control ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access to the management interface of the Traffic Router component could s | 0.7% | — |
| CVE-2025-29823 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-38043 | HIGH 7.8 | microsoft windows_10_1607 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26881 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix kernel crash when 1588 is received on HIP08 devices The HIP08 devices does not register the ptp devices, so the hdev->ptp is NULL, but the hardware can receive 1588 messages, | 0.7% | — |
| CVE-2023-35838 | MED 5.7 | wireguard wireguard The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected | 0.7% | — |
| CVE-2022-43954 | MED 4.3 | fortinet fortiportal An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page. | 0.7% | — |
| CVE-2022-23438 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and 6.4.9 and prior may allow an unauthenticated remote attacker to perform a reflected cross site scripting (XSS) | 0.7% | — |
| CVE-2022-1128 | MED 6.5 | google chrome Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60 allowed an attacker on the local network segment to leak cross-origin data via a crafted HTML page. | 0.7% | — |
| CVE-2021-3612 | HIGH 7.8 | debian debian_linux An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on t | 0.7% | — |
| CVE-2021-33113 | HIGH 8.1 | intel ac_1550_firmware Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access. | 0.7% | — |
| CVE-2021-29750 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 201778. | 0.7% | — |
| CVE-2007-1742 | LOW 3.7 | apache http_server suexec in Apache HTTP Server (httpd) 2.2.3 uses a partial comparison for verifying whether the current directory is within the document root, which might allow local users to perform unauthorized operations on incorrect directories, as demonstrated using "html | 0.7% | — |
| CVE-2026-29167 | CRIT 9.8 | apache http_server Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | 0.7% | — |
| CVE-2025-53787 | HIGH 8.2 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-42256 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix server re-repick on subrequest retry When a subrequest is marked for needing retry, netfs will call cifs_prepare_write() which will make cifs repick the server for the op before re | 0.7% | — |
| CVE-2023-44155 | HIGH 7.5 | acronis cyber_protect Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.7% | — |
| CVE-2023-35374 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 0.7% | — |