IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-20640 MED 6.1 cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali 0.8%
CVE-2022-20639 MED 6.1 cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali 0.8%
CVE-2022-20638 MED 6.1 cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali 0.8%
CVE-2022-20637 MED 6.1 cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali 0.8%
CVE-2022-20636 MED 6.1 cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali 0.8%
CVE-2022-20635 MED 6.1 cisco security_manager Multiple vulnerabilities in the web-based management interface of Cisco Security Manager could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks against a user of the interface. These vulnerabilities are due to insufficient vali 0.8%
CVE-2021-47328 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: iscsi: Fix conn use after free during resets If we haven't done a unbind target call we can race where iscsi_conn_teardown wakes up the EH thread and then frees the conn while those th 0.8%
CVE-2020-4259 MED 6.5 ibm sterling_file_gateway IBM Sterling File Gateway 2.2.0.0 through 6.0.3.1 could allow an authenticated user could manipulate cookie information and remove or add modules from the cookie to access functionality not authorized to. IBM X-Force ID: 175638. 0.8%
CVE-2019-9896 HIGH 7.8 opensuse backports_sle In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable. 0.8%
CVE-2018-1214 HIGH 7.0 dell emc_supportassist_enterprise Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to 0.8%
CVE-2017-12628 HIGH 7.8 apache james_server The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can onl 0.8%
CVE-2014-1458 LOW 3.5 fortinet fortiweb Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors. 0.8%
CVE-2013-5634 MED 4.3 linux linux_kernel arch/arm/kvm/arm.c in the Linux kernel before 3.10 on the ARM platform, when KVM is used, allows host OS users to cause a denial of service (NULL pointer dereference, OOPS, and host OS crash) or possibly have unspecified other impact by omitting vCPU initializ 0.8%
CVE-2026-47645 HIGH 8.8 microsoft 365_copilot Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. 0.8%
CVE-2025-27483 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.8%
CVE-2024-47604 HIGH 8.2 microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser. 0.8%
CVE-2024-27784 HIGH 8.8 fortinet fortiaiops Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files. 0.8%
CVE-2023-36418 HIGH 7.8 microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 0.8%
CVE-2026-21228 HIGH 8.1 microsoft azure_local Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-29847 HIGH 7.5 apache linkis A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the 0.8%
CVE-2025-21193 MED 6.5 microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability 0.8%
CVE-2024-46737 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix kernel crash if commands allocation fails If the commands allocation fails in nvmet_tcp_alloc_cmds() the kernel crashes in nvmet_tcp_release_queue_work() because of a NULL poi 0.8%
CVE-2024-40980 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drop_monitor: replace spin_lock by raw_spin_lock trace_drop_common() is called with preemption disabled, and it acquires a spin_lock. This is problematic for RT kernels because spin_locks ar 0.8%
CVE-2024-21309 HIGH 7.8 microsoft windows_11_21h2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 0.8%
CVE-2024-20682 HIGH 7.8 microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability 0.8%