IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-39884 MED 6.2 apache http_server A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code discl 0.9%
CVE-2023-38147 HIGH 8.8 microsoft windows_10_1507 Windows Miracast Wireless Display Remote Code Execution Vulnerability 0.9%
CVE-2022-42703 MED 5.5 linux linux_kernel mm/rmap.c in the Linux kernel before 5.19.7 has a use-after-free related to leaf anon_vma double reuse. 0.9%
CVE-2022-36123 HIGH 7.8 linux linux_kernel The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges. 0.9%
CVE-2022-35843 HIGH 8.1 fortinet fortios An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 through 6.4.9, 6.2 all versions, 6.0 all versions and FortiProxy SSH login component 7.0.0 through 7.0.5, 2.0.0 th 0.9%
CVE-2022-23030 MED 5.3 f5 big-ip_access_policy_manager On version 16.1.x before 16.1.2, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when the BIG-IP Virtual Edition (VE) uses the ixlv driver (which is used in SR-IOV mode and requires Intel X710/XL710/XXV710 family of network adapters 0.9%
CVE-2022-23028 MED 5.3 f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x, when global AFM SYN cookie protection (TCP Half Open flood vector) is activated in the AFM Device Dos or DOS profile, certain types of TCP conne 0.9%
CVE-2020-3167 HIGH 7.8 cisco adaptive_security_appliance_software A vulnerability in the CLI of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS). The vulnerability is due to insufficient input validation. An a 0.9%
CVE-2020-17076 HIGH 7.8 microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability 0.9%
CVE-2020-1596 MED 5.4 microsoft windows_10 <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.</p> <p>To exploit 0.9%
CVE-2017-0563 HIGH 7.8 linux linux_kernel An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp 0.9%
CVE-2014-3406 HIGH 7.1 cisco intrusion_prevention_system Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085 0.9%
CVE-2025-24043 HIGH 7.5 microsoft windbg Improper verification of cryptographic signature in .NET allows an authorized attacker to execute code over a network. 0.9%
CVE-2024-37358 HIGH 8.6 apache james_server Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7. 0.9%
CVE-2024-31079 MED 4.8 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connectio 0.9%
CVE-2024-28917 MED 6.2 microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability 0.9%
CVE-2024-20338 HIGH 7.3 cisco secure_client A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. A 0.9%
CVE-2023-34324 MED 4.9 linux linux_kernel Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of an eve 0.9%
CVE-2023-20272 MED 6.7 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. 0.9%
CVE-2021-24106 MED 5.5 microsoft windows_10 Windows DirectX Information Disclosure Vulnerability 0.9%
CVE-2021-24079 MED 5.5 microsoft windows_10 Windows Backup Engine Information Disclosure Vulnerability 0.9%
CVE-2021-24076 MED 5.5 microsoft windows_10 Microsoft Windows VMSwitch Information Disclosure Vulnerability 0.9%
CVE-2017-0430 HIGH 7.8 google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compr 0.9%
CVE-2010-4249 MED 4.9 fedoraproject fedora The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted u 0.9%
CVE-2024-20694 MED 5.5 microsoft windows_10_1607 Windows CoreMessaging Information Disclosure Vulnerability 0.9%