IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2024-47197 HIGH 7.5 apache maven_archetype Exposure of Sensitive Information to an Unauthorized Actor, Insecure Storage of Sensitive Information vulnerability in Maven Archetype Plugin. This issue affects Maven Archetype Plugin: from 3.2.1 before 3.3.0. Users are recommended to upgrade to version 3.3 0.8%
CVE-2024-38186 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0.8%
CVE-2023-33306 MED 6.5 fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter. 0.8%
CVE-2023-20087 MED 4.9 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insuffi 0.8%
CVE-2023-20077 MED 4.9 cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of an affected device. These vulnerabilities are due to insuffi 0.8%
CVE-2022-41031 HIGH 7.8 microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability 0.8%
CVE-2021-26874 HIGH 7.8 microsoft windows_10 Windows Overlay Filter Elevation of Privilege Vulnerability 0.8%
CVE-2019-1859 HIGH 7.2 cisco sf200-24_firmware A vulnerability in the Secure Shell (SSH) authentication process of Cisco Small Business Switches software could allow an attacker to bypass client-side certificate authentication and revert to password authentication. The vulnerability exists because OpenSSH 0.8%
CVE-2019-15218 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver. 0.8%
CVE-2018-0241 HIGH 7.4 cisco ios_xr A vulnerability in the UDP broadcast forwarding function of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to improper handling of UDP broadc 0.8%
CVE-2017-18509 HIGH 7.8 canonical ubuntu_linux An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel before 4.11. By setting a specific socket option, an attacker can control a pointer in kernel land and cause an inet_csk_listen_stop general protection fault, or potentially execute arbitrary code 0.8%
CVE-2017-12305 MED 6.7 cisco ip_phone_8800_series_firmware A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient input validation. An attacker could exp 0.8%
CVE-2015-2344 MED 5.4 vmware vrealize_automation Cross-site scripting (XSS) vulnerability in VMware vRealize Automation 6.x before 6.2.4 on Linux allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. 0.8%
CVE-2012-4092 MED 5.8 cisco unified_computing_system The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing a 0.8%
CVE-2026-69683 MED 6.5 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-56185 MED 6.5 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-50651 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50648 HIGH 7.5 microsoft .net Allocation of resources without limits or throttling in .NET Framework allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-50527 HIGH 7.5 microsoft .net Stack-based buffer overflow in .NET Framework allows an unauthorized attacker to deny service over a network. 0.8%
CVE-2026-42826 CRIT 10.0 microsoft azure_devops Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-33819 CRIT 10.0 microsoft bing Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-48768 MED 6.5 apache nuttx Release of Invalid Pointer or Reference vulnerability was discovered in fs/inode/fs_inoderemove code of the Apache NuttX RTOS that allowed root filesystem inode removal leading to a debug assert trigger (that is disabled by default), NULL pointer dereference ( 0.8%
CVE-2024-31391 MED 6.5 apache solr_operator Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentica 0.8%
CVE-2023-28505 HIGH 8.8 rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a buffer overflow in an API function, where a string is copied into a caller-provided buffer without checking the lengt 0.8%
CVE-2023-27873 MED 6.5 ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote authenticated attacker to obtain sensitive credential information using specially crafted XML input. IBM X-Force ID: 249654. 0.8%