IT
57.758 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.758 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2022-23238 MED 6.5 netapp storagegrid Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux kernel version less than 4.7.0 are susceptible to a vulnerability which could allow a remote unauthenticated attacker to view limited metric 0.7%
CVE-2019-17180 HIGH 7.8 valvesoftware steam_client Valve Steam Client before 2019-09-12 allows placing or appending partially controlled filesystem content, as demonstrated by file modifications on Windows in the context of NT AUTHORITY\SYSTEM. This could lead to denial of service, elevation of privilege, or u 0.7%
CVE-2014-3405 MED 4.8 cisco ios_xe Cisco IOS XE enables the IPv6 Routing Protocol for Low-Power and Lossy Networks (aka RPL) on both the Autonomic Control Plane (ACP) and external Autonomic Networking Infrastructure (ANI) interfaces, which allows remote attackers to conduct route-injection atta 0.7%
CVE-2025-30677 MED 6.5 apache pulsar Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This 0.7%
CVE-2025-21312 LOW 2.4 microsoft windows_10_1507 Windows Smart Card Reader Information Disclosure Vulnerability 0.7%
CVE-2024-43579 HIGH 7.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7%
CVE-2024-43578 HIGH 7.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7%
CVE-2024-38123 MED 4.4 microsoft windows_11_24h2 Windows Bluetooth Driver Information Disclosure Vulnerability 0.7%
CVE-2023-0882 HIGH 8.8 krontech single_connect Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Kron Tech Single Connect on Windows allows Privilege Abuse. This issue affects Single Connect: 2.16. 0.7%
CVE-2022-49670 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: linux/dim: Fix divide by 0 in RDMA DIM Fix a divide 0 error in rdma_dim_stats_compare() when prev->cpe_ratio == 0. CallTrace: Hardware name: H3C R4900 G3/RS33M2C9S, BIOS 2.00.37P21 03/12/ 0.7%
CVE-2022-22229 HIGH 8.4 juniper paragon_active_assurance_control_center An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability, a stored XSS (or persistent), in the Control Center Controller web pages of Juniper Networks Paragon Active Assurance (Formerly Netrounds) allows a high-priv 0.7%
CVE-2020-26080 MED 4.1 cisco iot_field_network_director A vulnerability in the user management functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to manage user information for users in different domains on an affected system. The vulnerability is due to improper d 0.7%
CVE-2012-5723 MED 6.1 cisco asr_1001 Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948. 0.7%
CVE-2026-78520 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-33823 CRIT 9.6 microsoft teams Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-21235 HIGH 7.3 microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2026-20096 MED 6.5 cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi 0.7%
CVE-2025-60728 MED 4.3 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2025-53149 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2024-53226 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() ib_map_mr_sg() allows ULPs to specify NULL as the sg_offset argument. The driver needs to check whether it is a NULL pointer bef 0.7%
CVE-2024-38155 MED 5.5 microsoft windows_10_1809 Security Center Broker Information Disclosure Vulnerability 0.7%
CVE-2023-47104 CRIT 9.8 vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered s 0.7%
CVE-2023-32018 HIGH 7.8 microsoft windows_11_22h2 Windows Hello Remote Code Execution Vulnerability 0.7%
CVE-2023-32008 HIGH 7.8 microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7%
CVE-2023-29370 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0.7%