57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-4259 | MED 6.5 | ibm sterling_file_gateway IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638. | 0.8% | — |
| CVE-2019-9896 | HIGH 7.8 | opensuse backports_sle In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable. | 0.8% | — |
| CVE-2018-1214 | HIGH 7.0 | dell emc_supportassist_enterprise Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to | 0.8% | — |
| CVE-2017-12628 | HIGH 7.8 | apache james_server The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can onl | 0.8% | — |
| CVE-2014-1458 | LOW 3.5 | fortinet fortiweb Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors. | 0.8% | — |
| CVE-2013-5634 | MED 4.3 | linux linux_kernel arch/arm/kvm/arm.c in the Linux kernel before 3.10 on the ARM platform, when KVM is used, allows host OS users to cause a denial of service (NULL pointer dereference, OOPS, and host OS crash) or possibly have unspecified other impact by omitting vCPU initializ | 0.8% | — |
| CVE-2026-39816 | HIGH 8.8 | apache nifi The optional extension component TinkerpopClientService is missing the Restricted annotation with the Execute Code Required Permission in Apache NiFi 2.0.0-M1 through 2.8.0. The TinkerpopClientService supports configuration of ByteCode Submission for the Scrip | 0.8% | — |
| CVE-2025-62199 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2025-48802 | MED 6.5 | microsoft windows_11_22h2 Improper certificate validation in Windows SMB allows an authorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-27737 | HIGH 8.6 | microsoft windows_10_1507 Improper input validation in Windows Security Zone Mapping allows an unauthorized attacker to bypass a security feature locally. | 0.8% | — |
| CVE-2024-42232 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: fix race between delayed_work() and ceph_monc_stop() The way the delayed work is handled in ceph_monc_stop() is prone to races with mon_fault() and possibly also finish_hunting(). | 0.8% | — |
| CVE-2024-26817 | MED 5.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: amdkfd: use calloc instead of kzalloc to avoid integer overflow This uses calloc instead of doing the multiplication which might overflow. | 0.8% | — |
| CVE-2023-23487 | MED 4.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to insufficient audit logging. IBM X-Force ID: 245918. | 0.8% | — |
| CVE-2022-22048 | MED 6.1 | microsoft windows_10 BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-47168 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFS: fix an incorrect limit in filelayout_decode_layout() The "sizeof(struct nfs_fh)" is two bytes too large and could lead to memory corruption. It should be NFS_MAXFHSIZE because that's t | 0.8% | — |
| CVE-2021-31972 | MED 5.5 | microsoft windows_10 Event Tracing for Windows Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31960 | MED 5.5 | microsoft windows_10 Windows Bind Filter Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31191 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28479 | MED 5.5 | microsoft windows_10 Windows CSC Service Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28446 | HIGH 7.1 | microsoft windows_10 Windows Portmapping Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28441 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28437 | MED 5.5 | microsoft windows_10 Windows Installer Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28435 | MED 5.5 | microsoft windows_10 Windows Event Tracing Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-28318 | MED 5.5 | microsoft windows_10 Windows GDI+ Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-21140 | MED 6.8 | google chrome Uninitialized use in USB in Google Chrome prior to 88.0.4324.96 allowed a local attacker to potentially perform out of bounds memory access via via a USB device. | 0.8% | — |