57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0854 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-19927 | MED 6.0 | linux linux_kernel In the Linux kernel 5.0.0-rc7 (as distributed in ubuntu/linux.git on kernel.ubuntu.com), mounting a crafted f2fs filesystem image and performing some operations can lead to slab-out-of-bounds read access in ttm_put_pages in drivers/gpu/drm/ttm/ttm_page_alloc.c | 0.8% | — |
| CVE-2018-9186 | MED 6.1 | fortinet fortiauthenticator A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows attacker to execute unauthorized script code via inject malicious scripts in HTTP referer header. | 0.8% | — |
| CVE-2026-49169 | HIGH 8.0 | microsoft windows_server_2025 Use after free in DNS Server allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-47643 | CRIT 9.8 | microsoft azure_stack_edge External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-24098 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later | 0.8% | — |
| CVE-2024-44940 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: fou: remove warn in gue_gro_receive on unsupported protocol Drop the WARN_ON_ONCE inn gue_gro_receive if the encapsulated type is not known or does not have a GRO handler. Such a packet is | 0.8% | — |
| CVE-2024-20451 | HIGH 7.5 | cisco spa_301_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA500 Series IP Phones could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. | 0.8% | — |
| CVE-2023-41677 | HIGH 7.5 | fortinet fortios A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, Fortinet FortiOS 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0 | 0.8% | — |
| CVE-2023-35389 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2026-63071 | CRIT 9.8 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code bypassing the Groovy security sandbox. This issue affect | 0.8% | — |
| CVE-2025-29803 | HIGH 7.3 | microsoft sql_server_management_studio Uncontrolled search path element in Visual Studio Tools for Applications and SQL Server Management Studio allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2024-38139 | HIGH 8.7 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-25090 | MED 5.4 | apache roller Insufficient input validation and sanitation in Profile name & screenname, Bookmark name & description and blogroll name features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not | 0.8% | — |
| CVE-2024-21340 | MED 4.6 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-27486 | MED 6.6 | fortinet fortiddos A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through 5.3.1, 5.2.0, 5.1.0, 5.0.0, 4.7.0, 4.6.0 and 4.5.0 and FortiDDoS-F version 6.3.0 | 0.8% | — |
| CVE-2018-10878 | HIGH 7.8 | canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. | 0.8% | — |
| CVE-2017-5646 | MED 6.8 | apache knox For versions of Apache Knox from 0.2.0 to 0.11.0 - an authenticated user may use a specially crafted URL to impersonate another user while accessing WebHDFS through Apache Knox. This may result in escalated privileges and unauthorized data access. While this a | 0.8% | — |
| CVE-2026-77906 | HIGH 8.8 | microsoft visual_studio_2026 Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-49163 | HIGH 8.8 | microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-21264 | HIGH 7.1 | microsoft visual_studio_code Files or directories accessible to external parties in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.8% | — |
| CVE-2024-41036 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Fix deadlock with the SPI chip variant When SMP is enabled and spinlocks are actually functional then there is a deadlock with the 'statelock' spinlock between ks8851_start_xmit | 0.8% | — |
| CVE-2024-30341 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability i | 0.8% | — |
| CVE-2023-27497 | CRIT 10.0 | sap diagnostics_agent Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation | 0.8% | — |
| CVE-2012-2853 | MED 6.8 | google chrome The webRequest API in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly interact with the Chrome Web Store, which allows remote attackers to cause a denial of service or possibly hav | 0.8% | — |