57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-27727 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_function_frame at src/njs_function.h. | 0.7% | — |
| CVE-2022-33875 | MED 5.4 | fortinet fortiadc An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to execute unauthorized code or c | 0.7% | — |
| CVE-2022-22368 | HIGH 7.5 | ibm spectrum_scale IBM Spectrum Scale 5.1.0 through 5.1.3.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 221012. | 0.7% | — |
| CVE-2022-0023 | MED 5.9 | paloaltonetworks pan-os An improper handling of exceptional conditions vulnerability exists in the DNS proxy feature of Palo Alto Networks PAN-OS software that enables a meddler-in-the-middle (MITM) to send specifically crafted traffic to the firewall that causes the service to resta | 0.7% | — |
| CVE-2021-41343 | MED 5.5 | microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-41336 | MED 5.5 | microsoft windows_11 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40475 | MED 5.5 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40472 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-40468 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-38663 | MED 5.5 | microsoft windows_10 Windows exFAT File System Information Disclosure Vulnerability | 0.7% | — |
| CVE-2020-2044 | LOW 3.3 | paloaltonetworks pan-os An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software. The opcmdhistory.log file was introduced to track oper | 0.7% | — |
| CVE-2020-2043 | LOW 3.3 | paloaltonetworks pan-os An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the | 0.7% | — |
| CVE-2020-1334 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE | 0.7% | — |
| CVE-2020-1265 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1282, CVE | 0.7% | — |
| CVE-2019-20357 | HIGH 7.8 | trendmicro antivirus_\+_security_2019 A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain | 0.7% | — |
| CVE-2013-0160 | LOW 2.1 | linux linux_kernel The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device. | 0.7% | — |
| CVE-2026-26083 | CRIT 9.8 | fortinet fortisandbox A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, FortiSandbox PaaS 23.4 all versions, FortiSandbox PaaS 23.3 all versions, FortiSandbox PaaS 23.1 all v | 0.7% | — |
| CVE-2025-49746 | CRIT 9.9 | microsoft azure_machine_learning Improper authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-52067 | MED 4.9 | apache nifi Apache NiFi 1.16.0 through 1.28.0 and 2.0.0-M1 through 2.0.0-M4 include optional debug logging of Parameter Context values during the flow synchronization process. An authorized administrator with access to change logging levels could enable debug logging for | 0.7% | — |
| CVE-2024-42152 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a possible leak when destroy a ctrl during qp establishment In nvmet_sq_destroy we capture sq->ctrl early and if it is non-NULL we know that a ctrl was allocated (in the admin con | 0.7% | — |
| CVE-2024-36916 | HIGH 7.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: blk-iocost: avoid out of bounds shift UBSAN catches undefined behavior in blk-iocost, where sometimes iocg->delay is shifted right by a number that is too large, resulting in undefined behav | 0.7% | — |
| CVE-2024-28903 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-24779 | MED 5.0 | apache superset Apache Superset with custom roles that include `can write on dataset` and without all data access permissions, allows for users to create virtual datasets to data they don't have access to. These users could then use those virtual datasets to get access to una | 0.7% | — |
| CVE-2023-34984 | HIGH 7.5 | fortinet fortiweb A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6 through 6.3.23 allows attacker to execute unauthorized code or commands via specially crafted HTTP requests. | 0.7% | — |
| CVE-2021-20444 | MED 6.1 | ibm maximo_for_civil_infrastructure IBM Maximo for Civil Infrastructure 7.6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr | 0.7% | — |