57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-47023 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix port event handling on init For some reason there might be a crash during ports creation if port events are handling at the same time because fw may send initial | 0.8% | — |
| CVE-2021-1481 | MED 4.3 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct Cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input | 0.8% | — |
| CVE-2020-6643 | MED 5.4 | fortinet fortiisolator An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attacker to perform a cross site scripting attack (XSS). | 0.8% | — |
| CVE-2020-3579 | MED 6.1 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-base | 0.8% | — |
| CVE-2020-3137 | MED 6.1 | cisco email_security_appliance A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev | 0.8% | — |
| CVE-2020-3136 | MED 6.1 | cisco jabber_guest A vulnerability in the web-based management interface of Cisco Jabber Guest could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerabi | 0.8% | — |
| CVE-2020-16993 | MED 5.4 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2018-21033 | MED 6.5 | hitachi automation_director A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token se | 0.8% | — |
| CVE-2011-2481 | MED 4.6 | apache tomcat Apache Tomcat 7.0.x before 7.0.17 permits web applications to replace an XML parser used for other web applications, which allows local users to read or modify the (1) web.xml, (2) context.xml, or (3) tld files of arbitrary web applications via a crafted appli | 0.8% | — |
| CVE-2026-9135 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur | 0.8% | — |
| CVE-2026-69507 | MED 5.7 | microsoft windows_11_23h2 Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-69349 | MED 5.7 | microsoft windows_10_1607 Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-68874 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-24307 | CRIT 9.3 | microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-12763 | MED 6.8 | pgadmin pgadmin_4 pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing speciall | 0.8% | — |
| CVE-2024-30065 | MED 5.5 | microsoft windows_10_1507 Windows Themes Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-20693 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-33146 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-30268 | CRIT 9.8 | cltphp cltphp CLTPHP <=6.0 is vulnerable to Improper Input Validation. | 0.8% | — |
| CVE-2022-20786 | MED 5.4 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerabili | 0.8% | — |
| CVE-2018-5803 | MED 5.5 | debian debian_linux In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash. | 0.8% | — |
| CVE-2018-0215 | MED 6.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera | 0.8% | — |
| CVE-2017-8561 | HIGH 7.0 | microsoft windows_10 Windows kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Ke | 0.8% | — |
| CVE-2017-6794 | MED 6.7 | cisco meeting_server A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administ | 0.8% | — |
| CVE-2026-41094 | HIGH 8.8 | microsoft data_formulator Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. | 0.8% | — |