IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2005-2709 MED 4.6 linux linux_kernel The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (kernel oops) and possibly execute code by opening an interface file in /proc/sys/net/ipv4/conf/, waiting until the interface is unregistered, t 1.0%
CVE-2025-49681 MED 6.5 microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2025-49671 MED 6.5 microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2022-31686 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. 1.0%
CVE-2021-29728 MED 4.9 ibm sterling_external_authentication_server IBM Sterling Secure Proxy 6.0.1, 6.0.2, 2.4.3.2, and 3.4.3.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal da 1.0%
CVE-2020-16853 HIGH 7.1 microsoft onedrive <p>An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links. An attacker who successfully exploited this vulnerability could overwrite a targeted file with an elevated status.</p> <p>To 1.0%
CVE-2019-12415 MED 5.5 apache poi In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can allow an attacker to read files from the local filesystem or from internal network resources via XML External En 1.0%
CVE-2017-0304 MED 5.4 f5 big-ip_advanced_firewall_manager A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact the Configuration Utility until there is a resync of the rules 1.0%
CVE-2013-0884 MED 6.8 google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors. 1.0%
CVE-2025-60006 MED 5.3 juniper junos_os_evolved Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthorized commands. When 1.0%
CVE-2024-49103 MED 4.3 microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability 1.0%
CVE-2024-49099 MED 4.3 microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability 1.0%
CVE-2024-49098 MED 4.3 microsoft windows_10_1809 Windows Wireless Wide Area Network Service (WwanSvc) Information Disclosure Vulnerability 1.0%
CVE-2022-27507 MED 6.5 citrix application_delivery_controller Authenticated denial of service 1.0%
CVE-2019-1590 HIGH 8.1 cisco nx-os A vulnerability in the Transport Layer Security (TLS) certificate validation functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an unauthenticated, remote attacker to perform insecure TLS client a 1.0%
CVE-2019-11599 HIGH 7.0 linux linux_kernel The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma layout or vma flags changes while it runs, which allows local users to obtain sensitive information, cause a denial of service, or possibly ha 1.0%
CVE-2018-0119 MED 4.7 cisco conference_director A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to interact with and view information on an affected device that would normally be prohibited. The vulnerability is due to t 1.0%
CVE-2015-0736 MED 6.8 cisco mediasense Cross-site request forgery (CSRF) vulnerability in Cisco MediaSense 10.5(1) and earlier allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuu16728. 1.0%
CVE-2015-0704 MED 6.8 cisco unified_meetingplace Multiple cross-site request forgery (CSRF) vulnerabilities in API features in Cisco Unified MeetingPlace 8.6(1.9) allow remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus95884. 1.0%
CVE-2013-0893 MED 6.8 google chrome Race condition in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media. 1.0%
CVE-2026-33844 CRIT 9.0 microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. 1.0%
CVE-2024-21330 HIGH 7.8 microsoft azure_automation Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability 1.0%
CVE-2021-23009 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP version 16.0.x before 16.0.1.1 and 15.1.x before 15.1.3, malformed HTTP/2 requests may cause an infinite loop which causes a Denial of Service for Data Plane traffic. TMM takes the configured HA action when the TMM process is aborted. There is no con 1.0%
CVE-2020-4299 MED 4.3 ibm sterling_file_gateway IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 6.0.3.1 could expose sensitive information to a user through a specially crafted HTTP request. IBM X-Force ID: 176606. 1.0%
CVE-2020-1269 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, 1.0%