IT
57.622 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.622 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2023-35346 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.7%
CVE-2023-35345 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.7%
CVE-2023-35344 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.7%
CVE-2020-29371 LOW 3.3 linux linux_kernel An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd. 0.7%
CVE-2019-6696 MED 6.1 fortinet fortios An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage. 0.7%
CVE-2019-3701 MED 4.4 canonical ubuntu_linux An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can cr 0.7%
CVE-2019-1764 HIGH 8.1 cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due t 0.7%
CVE-2019-16154 MED 6.1 fortinet fortiauthenticator An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. 0.7%
CVE-2009-0028 LOW 2.1 linux linux_kernel The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new proc 0.7%
CVE-2026-56649 MED 5.9 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-48323 CRIT 10.0 adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to 0.7%
CVE-2026-26145 MED 4.8 microsoft azure_synapse Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2024-56626 HIGH 8.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write An offset from client could be a negative value, It could allows to write data outside the bounds of the allocated buffer. Note that 0.7%
CVE-2024-38250 HIGH 7.8 microsoft 365_copilot Windows Graphics Component Elevation of Privilege Vulnerability 0.7%
CVE-2024-20358 MED 6.0 cisco adaptive_security_appliance_software A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the und 0.7%
CVE-2023-32331 HIGH 7.5 ibm sterling_connect\ IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. 0.7%
CVE-2022-45432 MED 5.3 dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices 0.7%
CVE-2022-22204 MED 5.3 juniper junos An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a partial Denial of Service 0.7%
CVE-2022-21963 MED 6.4 microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7%
CVE-2021-40447 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.7%
CVE-2011-2526 MED 4.4 apache tomcat Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or 0.7%
CVE-2007-6192 MED 4.3 citrix netscaler The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-p 0.7%
CVE-2026-70465 HIGH 8.1 fortinet forticlient A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in a position to alter or craft DNS respons 0.7%
CVE-2026-65099 HIGH 7.8 nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of 0.7%
CVE-2026-65096 HIGH 7.8 nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosur 0.7%