57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-20690 | MED 5.3 | cisco ata_190_firmware Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. Thes | 0.7% | — |
| CVE-2021-20420 | MED 4.3 | ibm security_guardium IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281. | 0.7% | — |
| CVE-2020-5425 | HIGH 7.9 | vmware single_sign-on_for_tanzu Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same userna | 0.7% | — |
| CVE-2020-3264 | HIGH 7.1 | cisco sd-wan_firmware A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending | 0.7% | — |
| CVE-2020-0896 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0849. | 0.7% | — |
| CVE-2019-15998 | MED 5.3 | cisco ios_xr A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerab | 0.7% | — |
| CVE-1999-0381 | HIGH 7.2 | debian debian_linux super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. | 0.7% | — |
| CVE-2026-69223 | CRIT 9.1 | apache allura Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommended to upgrade to version 1.19.1, which fixes the issue. | 0.7% | — |
| CVE-2025-49744 | HIGH 7.0 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-21598 | HIGH 7.5 | juniper junos An Out-of-bounds Read vulnerability in Juniper Networks Junos OS and Junos OS Evolved's routing protocol daemon (rpd) allows an unauthenticated, network-based attacker to send malformed BGP packets to a device configured with packet receive trace options enabl | 0.7% | — |
| CVE-2024-35853 | MED 6.4 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: mlxsw: spectrum_acl_tcam: Fix memory leak during rehash The rehash delayed work migrates filters from one region to another. This is done by iterating over all chunks (all the filters with t | 0.7% | — |
| CVE-2024-34457 | MED 6.5 | apache streampark On versions before 2.1.4, after a regular user successfully logs in, they can manually make a request using the authorization token to view everyone's user flink information, including executeSQL and config. Mitigation: all users should upgrade to 2.1.4 | 0.7% | — |
| CVE-2024-27782 | HIGH 8.1 | fortinet fortiaiops Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old session tokens to perform unauthorized operations via crafted requests. | 0.7% | — |
| CVE-2024-22369 | HIGH 7.8 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel SQL ComponentThis issue affects Apache Camel: from 3.0.0 before 3.21.4, from 3.22.0 before 3.22.1, from 4.0.0 before 4.0.4, from 4.1.0 before 4.4.0. Users are recommended to upgrade to version 4. | 0.7% | — |
| CVE-2023-41916 | MED 6.5 | apache linkis In Apache Linkis =1.4.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will trigger arbitrary file reading. Therefore, the parameters in the Mysql JDBC URL should | 0.7% | — |
| CVE-2022-20928 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a dif | 0.7% | — |
| CVE-2019-1289 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2011-1625 | MED 5.4 | cisco ios Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka B | 0.7% | — |
| CVE-2026-20818 | MED 6.2 | microsoft windows_server_2016 Insertion of sensitive information into log file in Windows Kernel allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-47176 | HIGH 7.8 | microsoft 365_apps '.../...//' in Microsoft Office Outlook allows an authorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-27733 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-45461 | MED 5.7 | apache cloudstack The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative Clou | 0.7% | — |
| CVE-2023-24882 | MED 5.5 | microsoft onedrive Microsoft OneDrive for Android Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-21794 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.7% | — |
| CVE-2022-30222 | HIGH 8.4 | microsoft windows_10 Windows Shell Remote Code Execution Vulnerability | 0.7% | — |