57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0247 | MED 4.7 | cisco aironet_access_point_software A vulnerability in Web Authentication (WebAuth) clients for the Cisco Wireless LAN Controller (WLC) and Aironet Access Points running Cisco IOS Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic. The vulnerabil | 0.9% | — |
| CVE-2017-7440 | MED 6.5 | gfi kerio_connect Kerio Connect 8.0.0 through 9.2.2, and Kerio Connect Client desktop application for Windows and Mac 9.2.0 through 9.2.2, when e-mail preview is enabled, allows remote attackers to conduct clickjacking attacks via a crafted e-mail message. | 0.9% | — |
| CVE-2017-6618 | MED 5.4 | cisco integrated_management_controller_supervisor A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied inpu | 0.9% | — |
| CVE-2017-16007 | MED 5.9 | cisco node-jose node-jose is a JavaScript implementation of the JSON Object Signing and Encryption (JOSE) for current web browsers and node.js-based servers. node-jose earlier than version 0.9.3 is vulnerable to an invalid curve attack. This allows an attacker to recover the | 0.9% | — |
| CVE-2017-12269 | MED 5.4 | cisco spark A vulnerability in the web UI of Cisco Spark Messaging Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web UI of the affected softwar | 0.9% | — |
| CVE-2016-8400 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without | 0.9% | — |
| CVE-2011-1021 | LOW 3.6 | linux linux_kernel drivers/acpi/debugfs.c in the Linux kernel before 3.0 allows local users to modify arbitrary kernel memory locations by leveraging root privileges to write to the /sys/kernel/debug/acpi/custom_method file. NOTE: this vulnerability exists because of an incomple | 0.9% | — |
| CVE-2009-0835 | LOW 3.6 | linux linux_kernel The __secure_computing function in kernel/seccomp.c in the seccomp subsystem in the Linux kernel 2.6.28.7 and earlier on the x86_64 platform, when CONFIG_SECCOMP is enabled, does not properly handle (1) a 32-bit process making a 64-bit syscall or (2) a 64-bit | 0.9% | — |
| CVE-2026-76433 | MED 5.3 | A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory tra | 0.9% | — |
| CVE-2026-21226 | HIGH 7.5 | microsoft azure_core_shared_client_library Deserialization of untrusted data in Azure Core shared client library for Python allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-20095 | MED 6.5 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi | 0.9% | — |
| CVE-2024-43518 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-42447 | CRIT 9.8 | apache apache-airflow-providers-fab Insufficient Session Expiration vulnerability in Apache Airflow Providers FAB. This issue affects Apache Airflow Providers FAB: 1.2.1 (when used with Apache Airflow 2.9.3) and FAB 1.2.0 for all Airflow versions. The FAB provider prevented the user from loggin | 0.9% | — |
| CVE-2024-38234 | MED 6.5 | microsoft windows_10_1507 Windows Networking Denial of Service Vulnerability | 0.9% | — |
| CVE-2024-38171 | HIGH 7.8 | microsoft 365_apps Microsoft PowerPoint Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38058 | MED 6.8 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2023-5168 | CRIT 9.8 | mozilla firefox A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are | 0.9% | — |
| CVE-2023-21793 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21791 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21790 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21789 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21788 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21787 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21786 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-21785 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |