57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21319 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21318 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21316 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21180 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally. | 0.9% | — |
| CVE-2024-3382 | HIGH 7.5 | paloaltonetworks pan-os A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that ar | 0.9% | — |
| CVE-2023-32047 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-23011 | HIGH 7.5 | f5 big-ip_access_policy_manager On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached En | 0.9% | — |
| CVE-2022-22180 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Over time, exploitation of this vulnerability | 0.9% | — |
| CVE-2022-22174 | HIGH 7.5 | juniper junos A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the con | 0.9% | — |
| CVE-2022-22171 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN whic | 0.9% | — |
| CVE-2022-22170 | HIGH 7.5 | juniper junos A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which | 0.9% | — |
| CVE-2022-22153 | HIGH 7.5 | juniper junos An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 allows an unauthenticated networ | 0.9% | — |
| CVE-2022-20914 | MED 4.9 | cisco identity_services_engine A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API o | 0.9% | — |
| CVE-2022-20744 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that rel | 0.9% | — |
| CVE-2021-42760 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive information from DB tables via crafted requests. | 0.9% | — |
| CVE-2010-0705 | HIGH 7.2 | avast avast_antivirus_home Aavmker4.sys in avast! 4.8 through 4.8.1368.0 and 5.0 before 5.0.418.0 running on Windows 2000 and XP does not properly validate input to IOCTL 0xb2d60030, which allows local users to cause a denial of service (system crash) or execute arbitrary code to gain p | 0.9% | — |
| CVE-2026-76433 | MED 5.3 | A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory tra | 0.9% | — |
| CVE-2026-21226 | HIGH 7.5 | microsoft azure_core_shared_client_library Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-20095 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi | 0.9% | — |
| CVE-2024-43518 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-42447 | CRIT 9.8 | apache apache-airflow-providers-fab Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from loggin | 0.9% | — |
| CVE-2024-38234 | MED 6.5 | microsoft windows_10_1507 Windows Networking Denial of Service Vulnerability | 0.9% | — |
| CVE-2024-38171 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38058 | MED 6.8 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2023-5168 | CRIT 9.8 | mozilla firefox A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are | 0.9% | — |