IT
57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.825 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-0302 MED 5.3 f5 big-ip_access_policy_manager In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters. 0.7%
CVE-2026-73019 MED 4.3 microsoft windows_10_1607 Improper resolution of path equivalence in Windows URL Moniker allows an unauthorized attacker to bypass a security feature over a network. 0.7%
CVE-2026-44185 HIGH 7.3 apache http_server Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. 0.7%
CVE-2024-38565 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ar5523: enable proper endpoint verification Syzkaller reports [1] hitting a warning about an endpoint in use not having an expected type to it. Fix the issue by checking for the exist 0.7%
CVE-2024-29062 HIGH 7.1 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-21753 MED 5.5 fortinet forticlient_endpoint_management_server A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker t 0.7%
CVE-2022-43863 MED 6.7 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425. 0.7%
CVE-2020-3462 MED 6.3 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-subm 0.7%
CVE-2020-26064 HIGH 8.1 cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Enti 0.7%
CVE-2020-11990 LOW 3.3 apache cordova We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access 0.7%
CVE-2019-18568 HIGH 8.8 avira free_antivirus Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user. 0.7%
CVE-2009-4914 HIGH 7.8 cisco asa_5580 Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879 0.7%
CVE-2026-69268 HIGH 8.8 microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-50505 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-50500 HIGH 7.5 microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-50340 HIGH 8.5 microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2025-54090 MED 6.3 apache http_server A bug in Apache HTTP Server 2.4.64 results in all "RewriteCond expr ..." tests evaluating as "true". Users are recommended to upgrade to version 2.4.65, which fixes the issue. 0.7%
CVE-2024-49114 HIGH 7.8 microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability 0.7%
CVE-2024-45217 HIGH 8.1 apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that 0.7%
CVE-2024-42516 HIGH 7.5 apache http_server HTTP response splitting in the core of Apache HTTP Server allows an attacker who can manipulate the Content-Type response headers of applications hosted or proxied by the server can split the HTTP response. This vulnerability was described as CVE-2023-38709 b 0.7%
CVE-2023-28295 HIGH 7.8 microsoft 365_apps Microsoft Publisher Remote Code Execution Vulnerability 0.7%
CVE-2023-28287 HIGH 7.8 microsoft 365_apps Microsoft Publisher Remote Code Execution Vulnerability 0.7%
CVE-2022-34167 MED 5.4 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within 0.7%
CVE-2022-34166 MED 5.4 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust 0.7%
CVE-2022-20868 MED 4.7 cisco asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attacker to elevate privileges on an affected system. The attacker n 0.7%