57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-28248 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-38411 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interacti | 0.7% | — |
| CVE-2022-30213 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.7% | — |
| CVE-2021-20441 | MED 5.9 | ibm security_verify_bridge IBM Security Verify Bridge uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196617. | 0.7% | — |
| CVE-2020-4658 | MED 6.1 | ibm sterling_file_gateway IBM Sterling File Gateway 2.2.0.0 through 6.0.3.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit | 0.7% | — |
| CVE-2020-4657 | MED 6.1 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator 5.2.0.0 through 6.0.3.2 Standard Edition is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credent | 0.7% | — |
| CVE-2020-4183 | MED 6.1 | ibm security_guardium IBM Security Guardium 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 0.7% | — |
| CVE-2019-4681 | MED 6.1 | ibm tivoli_netcool\/impact IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi | 0.7% | — |
| CVE-2018-5506 | CRIT 9.8 | f5 big-ip_access_policy_manager In F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.1, 11.5.1-11.5.5, or 11.2.1 the Apache modules apache_auth_token_mod and mod_auth_f5_auth_token.cpp allow possible unauthenticated bruteforce on the em_server_ip authorization parameter to obtain which SSL client certif | 0.7% | — |
| CVE-2007-1734 | HIGH 7.2 | linux linux_kernel The DCCP support in the do_dccp_getsockopt function in net/dccp/proto.c in Linux kernel 2.6.20 and later does not verify the upper bounds of the optlen value, which allows local users running on certain architectures to read kernel memory or cause a denial of | 0.7% | — |
| CVE-2026-42934 | MED 4.8 | f5 dos NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charset, and charset_map and proxy_pass with disabled buffering ("off") directives are configured, unauthenticated attackers can send requests tha | 0.7% | — |
| CVE-2024-40957 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: seg6: fix parameter passing when calling NF_HOOK() in End.DX4 and End.DX6 behaviors input_action_end_dx4() and input_action_end_dx6() are called NF_HOOK() for PREROUTING hook, in PREROUTING | 0.7% | — |
| CVE-2024-29064 | MED 6.2 | microsoft windows_10_1507 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-26241 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-20351 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the TCP/IP traffic handling function of the Snort Detection Engine of Cisco Firepower Threat Defense (FTD) Software and Cisco FirePOWER Services could allow an unauthenticated, remote attacker to cause legitimate network traffic to be droppe | 0.7% | — |
| CVE-2023-20061 | MED 6.5 | cisco packaged_contact_center_enterprise Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates t | 0.7% | — |
| CVE-2022-22713 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-21905 | MED 4.6 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2021-41374 | MED 6.7 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.7% | — |
| CVE-2020-9383 | HIGH 7.1 | canonical ubuntu_linux An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | 0.7% | — |
| CVE-2020-26068 | MED 5.5 | cisco roomos A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient access authorization. An | 0.7% | — |
| CVE-2020-0822 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Language Pack Installer improperly handles file operations, aka 'Windows Language Pack Installer Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2014-7999 | HIGH 7.7 | cisco meraki_mr Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow remote authenticated users to install arbitrary firmware by leveraging unspecified HTTP handler access on the local network, aka Cisco-Meraki defect ID 00478565. | 0.7% | — |
| CVE-2026-53176 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN In drivers/infiniband/ulp/isert/ib_isert.c, isert_login_recv_done() computes the login request payload length as wc->byte_len minus | 0.7% | — |
| CVE-2026-48204 | CRIT 9.8 | apache camel Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs producer selects the GridFS operation to perform from the gridfs.operation Exchange header when the endpoint's operati | 0.7% | — |