57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26415 | HIGH 7.7 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x, when running in Appliance mode, an authenticated user assigned the Administrator | 0.7% | — |
| CVE-2022-23029 | MED 5.3 | f5 big-ip_access_policy_manager On BIG-IP version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile is configured on a virtual server, undisclosed traffic can cause an increase in memory resource utilizat | 0.7% | — |
| CVE-2020-4548 | LOW 2.7 | ibm content_navigator IBM Content Navigator 3.0.7 and 3.0.8 is vulnerable to improper input validation. A malicious administrator could bypass the user interface and send requests to the IBM Content Navigator server with illegal characters that could be stored in the IBM Content Na | 0.7% | — |
| CVE-2020-3557 | MED 5.3 | cisco secure_firewall_management_center A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificat | 0.7% | — |
| CVE-2020-17075 | HIGH 7.8 | microsoft windows_10 Windows USO Core Worker Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-1423 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Subsystem for Linux handles files, aka 'Windows Subsystem for Linux Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2019-6607 | MED 6.8 | f5 big-ip_application_security_manager On BIG-IP ASM 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3, 13.0.0-13.1.1.3, and 14.0.0-14.0.0.2, there is a stored cross-site scripting vulnerability in an ASM violation viewed in the Configuration utility. In the worst case, an attacker can store a CSRF which | 0.7% | — |
| CVE-2019-1848 | CRIT 9.3 | cisco digital_network_architecture_center A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, adjacent attacker to bypass authentication and access critical internal services. The vulnerability is due to insufficient access restriction to ports necessary | 0.7% | — |
| CVE-2019-15997 | MED 6.7 | cisco dna_spaces\ A vulnerability in Cisco DNA Spaces: Connector could allow an authenticated, local attacker to perform a command injection attack and execute arbitrary commands on the underlying operating system as root. The vulnerability is due to insufficient validation of | 0.7% | — |
| CVE-2017-5066 | MED 6.5 | google chrome Insufficient consistency checks in signature handling in the networking stack in Google Chrome prior to 58.0.3029.81 for Mac, Windows, and Linux, and 58.0.3029.83 for Android, allowed a remote attacker to incorrectly accept a badly formed X.509 certificate via | 0.7% | — |
| CVE-2009-3692 | HIGH 7.2 | sun virtualbox Unspecified vulnerability in the VBoxNetAdpCtl configuration tool in Sun VirtualBox 3.0.x before 3.0.8 on Solaris x86, Linux, and Mac OS X allows local users to gain privileges via unknown vectors. | 0.7% | — |
| CVE-2006-1342 | LOW 2.1 | linux linux_kernel net/ipv4/af_inet.c in Linux kernel 2.4 does not clear sockaddr_in.sin_zero before returning IPv4 socket names from the (1) getsockname, (2) getpeername, and (3) accept functions, which allows local users to obtain portions of potentially sensitive memory. | 0.7% | — |
| CVE-2026-62827 | HIGH 8.8 | microsoft sharepoint_server Improper authentication in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-24343 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue. | 0.7% | — |
| CVE-2026-23570 | MED 6.5 | teamviewer digital_employee_experience A missing validation of a user-controlled value in the TeamViewer DEX Client (former 1E Client) - Content Distribution Service (NomadBranch.exe) prior version 26.1 for Windows allows an adjacent network attacker to tamper with log timestamps via crafted UDP Sy | 0.7% | — |
| CVE-2025-21419 | HIGH 7.1 | microsoft windows_10_1507 Windows Setup Files Cleanup Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-3841 | MED 6.1 | fedoraproject fedora Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium) | 0.7% | — |
| CVE-2024-38133 | HIGH 7.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-26253 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-26252 | MED 6.8 | microsoft windows_10_1507 Windows rndismp6.sys Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28248 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-38411 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0.7% | — |
| CVE-2022-30213 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-20441 | MED 5.9 | ibm security_verify_bridge IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617. | 0.7% | — |
| CVE-2020-4658 | MED 6.1 | ibm sterling_file_gateway IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit | 0.7% | — |