57.701 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.701 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-23316 | CRIT 9.8 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause a remote code execution by manipulating the model name parameter in the model control APIs. A successful exploit of this vulnerab | 0.7% | — |
| CVE-2024-41178 | HIGH 7.5 | apache arrow Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens. On certain error conditions, the logs may contain the OIDC token passed to AssumeRol | 0.7% | — |
| CVE-2024-30382 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to m | 0.7% | — |
| CVE-2023-37464 | HIGH 8.6 | cisco cjose OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). The AES GCM decryption routine incorrectly uses the Tag length from the actual Authentication Tag provided in the JWE. The spec says that a fixed length of 16 octet | 0.7% | — |
| CVE-2023-22337 | HIGH 7.5 | intel unison_software Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2022-29135 | HIGH 7.0 | microsoft windows_server Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-32585 | HIGH 7.2 | fortinet fortiwan An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests. | 0.7% | — |
| CVE-2021-29694 | HIGH 7.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 200258. | 0.7% | — |
| CVE-2021-26413 | MED 6.2 | microsoft windows_10 Windows Installer Spoofing Vulnerability | 0.7% | — |
| CVE-2021-20419 | HIGH 7.5 | ibm security_guardium IBM Security Guardium 11.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196280. | 0.7% | — |
| CVE-2021-20337 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 194448. | 0.7% | — |
| CVE-2020-24419 | HIGH 7.0 | adobe after_effects Adobe After Effects version 17.1.1 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.7% | — |
| CVE-2018-0364 | HIGH 8.8 | cisco unified_communications_domain_manager A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The | 0.7% | — |
| CVE-2018-0270 | HIGH 8.8 | cisco iot_field_network_director A vulnerability in the web-based management interface of Cisco IoT Field Network Director (IoT-FND) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and alter the data of existing users and groups on an affe | 0.7% | — |
| CVE-2026-42402 | HIGH 7.5 | apache neethi Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbou | 0.7% | — |
| CVE-2026-33929 | MED 4.3 | apache pdfbox Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are re | 0.7% | — |
| CVE-2026-33109 | CRIT 9.9 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-32175 | MED 4.3 | microsoft .net A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker | 0.7% | — |
| CVE-2025-62207 | HIGH 8.6 | microsoft azure_monitor Azure Monitor Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21188 | MED 6.0 | microsoft azure_network_watcher Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-35277 | HIGH 8.6 | fortinet fortimanager A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the | 0.7% | — |
| CVE-2024-30329 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0.7% | — |
| CVE-2024-30030 | HIGH 7.8 | microsoft windows_server_2008 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30028 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-29992 | MED 5.5 | microsoft azure_identity_library_for_.net Azure Identity Library for .NET Information Disclosure Vulnerability | 0.7% | — |