57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22998 | HIGH 8.0 | westerndigital my_cloud_home_duo_firmware Implemented protections on AWS credentials that were not properly protected. | 0.8% | — |
| CVE-2022-22152 | HIGH 7.7 | juniper contrail_service_orchestration A Protection Mechanism Failure vulnerability in the REST API of Juniper Networks Contrail Service Orchestration allows one tenant on the system to view confidential configuration details of another tenant on the same system. By utilizing the REST API, one tena | 0.8% | — |
| CVE-2020-2035 | LOW 3.0 | paloaltonetworks pan-os When SSL/TLS Forward Proxy Decryption mode has been configured to decrypt the web transactions, the PAN-OS URL filtering feature inspects the HTTP Host and URL path headers for policy enforcement on the decrypted HTTPS web transactions but does not consider Se | 0.8% | — |
| CVE-2017-5035 | HIGH 8.1 | debian debian_linux Google Chrome prior to 57.0.2987.98 for Windows and Mac had a race condition, which could cause Chrome to display incorrect certificate information for a site. | 0.8% | — |
| CVE-2016-8395 | MED 4.7 | linux linux_kernel A denial of service vulnerability in the NVIDIA camera driver could enable an attacker to cause a local permanent denial of service, which may require reflashing the operating system to repair the device. This issue is rated as High due to the possibility of l | 0.8% | — |
| CVE-2014-3820 | MED 4.3 | juniper junos_pulse_access_control_service Cross-site scripting (XSS) vulnerability in the SSL VPN/UAC web server in the Juniper Junos Pulse Secure Access Service (SSL VPN) devices with IVE OS 7.1 before 7.1r16, 7.4 before 7.4r3, and 8.0 before 8.0r1 and the Juniper Junos Pulse Access Control Service d | 0.8% | — |
| CVE-2011-3355 | HIGH 7.3 | gnome evolution-data-server3 evolution-data-server3 3.0.3 through 3.2.1 used insecure (non-SSL) connection when attempting to store sent email messages into the Sent folder, when the Sent folder was located on the remote server. An attacker could use this flaw to obtain login credentials | 0.8% | — |
| CVE-2009-0058 | MED 6.1 | cisco 4400_wireless_lan_controller The Cisco Wireless LAN Controller (WLC), Cisco Catalyst 6500 Wireless Services Module (WiSM), and Cisco Catalyst 3750 Integrated Wireless LAN Controller with software 4.x before 4.2.176.0 and 5.x before 5.2 allow remote attackers to cause a denial of service ( | 0.8% | — |
| CVE-2026-71257 | HIGH 7.5 | apache wicket Apache Wicket enforces the upload limits configured on a form or upload field while parsing a multipart request with Apache Commons FileUpload. If the request body has already been consumed by another component, Commons FileUpload returns no items and Wicket f | 0.8% | — |
| CVE-2026-69724 | HIGH 8.8 | microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-67260 | HIGH 7.3 | apache airflow Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deserializes the task instance's `next_kwargs` without an allow-list, so a Dag author — who controls that value throug | 0.8% | — |
| CVE-2026-65927 | HIGH 7.5 | apache tomcat Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1. | 0.8% | — |
| CVE-2024-56180 | CRIT 9.8 | apache eventmesh CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian | 0.8% | — |
| CVE-2024-24773 | MED 4.9 | apache superset Improper parsing of nested SQL statements on SQLLab would allow authenticated users to surpass their data authorization scope. This issue affects Apache Superset: before 3.0.4, from 3.1.0 before 3.1.1. Users are recommended to upgrade to version 3.1.1, which | 0.8% | — |
| CVE-2022-24513 | HIGH 7.8 | microsoft visual_studio_2019 Visual Studio Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-0912 | HIGH 7.0 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Function Discovery SSDP Provider improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run | 0.8% | — |
| CVE-2019-7962 | HIGH 7.8 | adobe illustrator_cc Adobe Illustrator CC versions 23.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. | 0.8% | — |
| CVE-2016-9194 | MED 6.5 | cisco wireless_lan_controller A vulnerability in 802.11 Wireless Multimedia Extensions (WME) action frame processing in Cisco Wireless LAN Controller (WLC) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to i | 0.8% | — |
| CVE-2016-1238 | HIGH 7.8 | apache spamassassin (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/b | 0.8% | — |
| CVE-2013-6014 | CRIT 9.3 | juniper junos Juniper Junos 10.4 before 10.4S15, 11.4 before 11.4R9, 11.4X27 before 11.4X27.44, 12.1 before 12.1R7, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.2 before 12.2R6, 12.3 before 12.3R3, 13.1 before 13.1R3, and 13.2 before 13.2R1, when Proxy ARP is | 0.8% | — |
| CVE-2026-62902 | MED 6.5 | microsoft .net Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-57100 | CRIT 9.9 | microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-54998 | HIGH 8.8 | microsoft exchange_online Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50444 | HIGH 8.8 | microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-50360 | HIGH 8.8 | microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |