57.918 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.918 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-10878 | HIGH 7.8 | canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. | 0.8% | — |
| CVE-2017-5646 | MED 6.8 | apache knox For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this a | 0.8% | — |
| CVE-2026-49169 | HIGH 8.0 | microsoft windows_server_2025 Use after free in DNS Server allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-47643 | CRIT 9.8 | microsoft azure_stack_edge External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-24098 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later | 0.8% | — |
| CVE-2024-44940 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is not known or does not have a GRO handler. Such a packet is | 0.8% | — |
| CVE-2024-20451 | HIGH 7.5 | cisco spa_301_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. | 0.8% | — |
| CVE-2023-41677 | HIGH 7.5 | fortinet fortios A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0 | 0.8% | — |
| CVE-2023-35389 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2026-65637 | CRIT 9.8 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrad | 0.8% | — |
| CVE-2023-48362 | HIGH 8.8 | apache drill XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands via a malicious XML file. Users are recommended to upgrade to version 1.21.2, which fixes this issue. | 0.8% | — |
| CVE-2023-36428 | MED 5.5 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-36406 | MED 5.5 | microsoft windows_11_21h2 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2023-28240 | HIGH 8.8 | microsoft windows_server_2008 Windows Network Load Balancing Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-37424 | MED 6.5 | opennebula opennebula Files or Directories Accessible to External Parties vulnerability in OpenNebula on Linux allows File Discovery. | 0.8% | — |
| CVE-2020-0854 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-19927 | MED 6.0 | linux linux_kernel In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c | 0.8% | — |
| CVE-2018-9186 | MED 6.1 | fortinet fortiauthenticator A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. | 0.8% | — |
| CVE-2025-21363 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-28902 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-26255 | MED 5.5 | microsoft windows_10_1809 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-26207 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2024-20444 | MED 5.5 | cisco nexus_dashboard_fabric_controller A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. | 0.8% | — |
| CVE-2023-36398 | MED 6.5 | microsoft windows_10_1507 Windows NTFS Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-40732 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0.8% | — |