57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-47197 | HIGH 7.5 | apache maven_archetype Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3 | 0.8% | — |
| CVE-2024-38186 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-33306 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. | 0.8% | — |
| CVE-2023-20087 | MED 4.9 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insuffi | 0.8% | — |
| CVE-2023-20077 | MED 4.9 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insuffi | 0.8% | — |
| CVE-2022-41031 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-26874 | HIGH 7.8 | microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2019-1859 | HIGH 7.2 | cisco sf200-24_firmware A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication. The vulnerability exists because OpenSSH | 0.8% | — |
| CVE-2019-15218 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver. | 0.8% | — |
| CVE-2018-0241 | HIGH 7.4 | cisco ios_xr A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadc | 0.8% | — |
| CVE-2017-18509 | HIGH 7.8 | canonical ubuntu_linux An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code | 0.8% | — |
| CVE-2017-12305 | MED 6.7 | cisco ip_phone_8800_series_firmware A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. An attacker could exp | 0.8% | — |
| CVE-2015-2344 | MED 5.4 | vmware vrealize_automation Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | 0.8% | — |
| CVE-2012-4092 | MED 5.8 | cisco unified_computing_system The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing a | 0.8% | — |
| CVE-2026-69683 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-56185 | MED 6.5 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-50651 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50648 | HIGH 7.5 | microsoft .net Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-50527 | HIGH 7.5 | microsoft .net Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.8% | — |
| CVE-2026-42826 | CRIT 10.0 | microsoft azure_devops Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-33819 | CRIT 10.0 | microsoft bing Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-48768 | MED 6.5 | apache nuttx Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference ( | 0.8% | — |
| CVE-2024-31391 | MED 6.5 | apache solr_operator Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentica | 0.8% | — |
| CVE-2023-28505 | HIGH 8.8 | rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the lengt | 0.8% | — |
| CVE-2023-27873 | MED 6.5 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654. | 0.8% | — |