57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0462 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the Qualcomm Seemp driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 1.0% | — |
| CVE-2008-3761 | MED 4.9 | vmware vmware_workstation hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VMware Server 1.0.x before 1.0.9 build 156507 and 2.0.x before 2.0.1 build 156745 uses the METHOD_NEITHER communication method for IOCTLs, whi | 1.0% | — |
| CVE-2025-50151 | HIGH 8.8 | apache jena File access paths in configuration files uploaded by users with administrator access are not validated. This issue affects Apache Jena version up to 5.4.0. Users are recommended to upgrade to version 5.5.0, which does not allow arbitrary configuration upload | 1.0% | — |
| CVE-2025-29840 | HIGH 8.8 | microsoft windows_10_1507 Stack-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-29057 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2024-22275 | MED 4.9 | vmware cloud_foundation The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | 1.0% | — |
| CVE-2023-37936 | CRIT 9.8 | fortinet fortiswitch A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via cr | 1.0% | — |
| CVE-2023-36393 | HIGH 7.8 | microsoft windows_10_1507 Windows User Interface Application Core Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-43869 | MED 6.5 | ibm elastic_storage_system IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string a | 1.0% | — |
| CVE-2022-20808 | HIGH 7.7 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous dev | 1.0% | — |
| CVE-2021-22038 | HIGH 8.8 | vmware installbuilder On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict a | 1.0% | — |
| CVE-2021-22003 | HIGH 7.5 | vmware cloud_foundation VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based | 1.0% | — |
| CVE-2020-8950 | HIGH 7.8 | amd user_experience_program The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that poin | 1.0% | — |
| CVE-2019-20096 | MED 5.5 | canonical ubuntu_linux In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b. | 1.0% | — |
| CVE-2019-17655 | MED 5.3 | fortinet fortios A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be | 1.0% | — |
| CVE-2019-10084 | HIGH 7.5 | apache impala In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms | 1.0% | — |
| CVE-2011-1576 | MED 5.7 | linux linux_kernel The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to ca | 1.0% | — |
| CVE-2024-26257 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-25069 | HIGH 8.8 | trendmicro txone_stellarone TXOne StellarOne has an improper access control privilege escalation vulnerability in every version before V2.0.1160 that could allow a malicious, falsely authenticated user to escalate his privileges to administrator level. With these privileges, an attacker | 1.0% | — |
| CVE-2023-21712 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-20409 | MED 5.9 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive infor | 1.0% | — |
| CVE-2021-0284 | HIGH 7.5 | juniper junos A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker to send specific sequences of packets to the device thereby causing a Denial of Service (DoS). By repeatedly sending these sequences of packets to the device, a | 1.0% | — |
| CVE-2021-0283 | HIGH 7.5 | juniper junos A buffer overflow vulnerability in the TCP/IP stack of Juniper Networks Junos OS allows an attacker to send specific sequences of packets to the device thereby causing a Denial of Service (DoS). By repeatedly sending these sequences of packets to the device, a | 1.0% | — |
| CVE-2020-3468 | MED 5.4 | cisco sd-wan_firmware A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface imp | 1.0% | — |
| CVE-2017-5036 | HIGH 7.8 | debian debian_linux A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file. | 1.0% | — |