57.725 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.725 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-15221 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver. | 0.7% | — |
| CVE-2019-15219 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver. | 0.7% | — |
| CVE-2019-1177 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the rpcss.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticated | 0.7% | — |
| CVE-2019-1175 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the psmsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 0.7% | — |
| CVE-2019-1174 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the PsmServiceExtHost.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally a | 0.7% | — |
| CVE-2017-6719 | MED 6.7 | cisco ios_xr A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with root privileges, aka Command Injection. More Information: CSCvb99406. Known Affected Releases: 6.2. | 0.7% | — |
| CVE-2013-1226 | MED 6.1 | cisco nexus_7000 The Ethernet frame-forwarding implementation in Cisco NX-OS on Nexus 7000 devices allows remote attackers to cause a denial of service (forwarding loop and service outage) via a crafted frame, aka Bug ID CSCug47098. | 0.7% | — |
| CVE-2025-21214 | MED 4.2 | microsoft windows_10_1507 Windows BitLocker Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-46763 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fou: Fix null-ptr-deref in GRO. We observed a null-ptr-deref in fou_gro_receive() while shutting down a host. [0] The NULL pointer is sk->sk_user_data, and the offset 8 is of protocol in s | 0.7% | — |
| CVE-2024-38050 | HIGH 7.8 | microsoft windows_10_1507 Windows Workstation Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30049 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26854 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ice: fix uninitialized dplls mutex usage The pf->dplls.lock mutex is initialized too late, after its first use. Move it to the top of ice_dpll_init. Note that the "err_exit" error path destr | 0.7% | — |
| CVE-2023-43021 | MED 5.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 2661 | 0.7% | — |
| CVE-2023-42785 | MED 6.5 | fortinet fortios A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request. | 0.7% | — |
| CVE-2023-35080 | HIGH 7.8 | ivanti secure_access_client A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, den | 0.7% | — |
| CVE-2022-34306 | MED 5.4 | ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, ca | 0.7% | — |
| CVE-2022-20830 | MED 5.3 | cisco catalyst_sd-wan_manager A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exis | 0.7% | — |
| CVE-2021-47244 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix out of bounds when parsing TCP options The TCP option parser in mptcp (mptcp_get_options) could read one byte out of bounds. When the length is 1, the execution flow gets into the | 0.7% | — |
| CVE-2021-31386 | MED 5.3 | juniper junos A Protection Mechanism Failure vulnerability in the J-Web HTTP service of Juniper Networks Junos OS allows a remote unauthenticated attacker to perform Person-in-the-Middle (PitM) attacks against the device. This issue affects: Juniper Networks Junos OS 12.3 v | 0.7% | — |
| CVE-2019-1750 | HIGH 7.4 | cisco ios_xe A vulnerability in the Easy Virtual Switching System (VSS) of Cisco IOS XE Software on Catalyst 4500 Series Switches could allow an unauthenticated, adjacent attacker to cause the switches to reload. The vulnerability is due to incomplete error handling when p | 0.7% | — |
| CVE-2018-17195 | HIGH 7.5 | apache nifi The template upload API endpoint accepted requests from different domain when sent in conjunction with ARP spoofing + man in the middle (MiTM) attack, resulting in a CSRF attack. The required attack vector is complex, requiring a scenario with client certifica | 0.7% | — |
| CVE-2017-3129 | MED 6.1 | fortinet fortiweb A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an improperly sanitized POST parameter in the FortiWeb Site Publisher feature. | 0.7% | — |
| CVE-2012-2119 | MED 5.2 | linux linux_kernel Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of service (crash) via a long descriptor with a long vector length. | 0.7% | — |
| CVE-2026-68784 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68781 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |