IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2013-1151 HIGH 7.1 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5), 8.5 before 8.5(1.17), 8.6 before 8.6(1.10), and 8.7 before 8.7(1.3) allow remote a 0.7%
CVE-2026-80096 HIGH 8.8 microsoft windows_10_1607 Out-of-bounds read in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2023-52741 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: Fix use-after-free in rdata->read_into_pages() When the network status is unstable, use-after-free may occur when read data from the server. BUG: KASAN: use-after-free in readpages_ 0.7%
CVE-2021-22040 MED 6.7 vmware cloud_foundation VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process runn 0.7%
CVE-2020-16988 MED 6.9 microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability 0.7%
CVE-2019-12619 MED 6.5 cisco sd-wan_firmware A vulnerability in the web interface for Cisco SD-WAN Solution vManage could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficient validation of user-s 0.7%
CVE-2018-10651 MED 6.1 citrix xenmobile_server There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. 0.7%
CVE-2016-1419 HIGH 8.1 cisco aironet_access_point_software Cisco Access Point devices with software 8.2(102.43) allow remote attackers to cause a denial of service (device reload) via crafted ARP packets, aka Bug ID CSCuy55803. 0.7%
CVE-2010-4247 MED 5.5 citrix xen The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consump 0.7%
CVE-2026-72323 CRIT 9.8 In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() A race condition exists between device teardown (inetdev_destroy) and incoming IGMP query processing (igmp_rcv), leading to a Use-After 0.7%
CVE-2026-69989 HIGH 8.1 microsoft windows_10_1607 Use after free in DNS Server allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2026-23662 HIGH 7.5 microsoft azure_iot_explorer Missing authentication for critical function in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2024-42247 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wireguard: allowedips: avoid unaligned 64-bit memory accesses On the parisc platform, the kernel issues kernel warnings because swap_endian() tries to load a 128-bit IPv6 address from an una 0.7%
CVE-2024-38254 MED 5.5 microsoft windows_10_1507 Windows Authentication Information Disclosure Vulnerability 0.7%
CVE-2024-26877 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: crypto: xilinx - call finalize with bh disabled When calling crypto_finalize_request, BH should be disabled to avoid triggering the following calltrace: ------------[ cut here ]-------- 0.7%
CVE-2023-44252 HIGH 8.8 fortinet fortiwan ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 through 5.1.2 may allow an authenticated attacker to escalate his privileges via HTTP or HTTPs requests with cr 0.7%
CVE-2023-29181 HIGH 8.8 fortinet fortios A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, 2.0.0 through 2.0.12, 1.2.0 thro 0.7%
CVE-2022-38381 MED 5.3 fortinet fortiadc An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web 0.7%
CVE-2019-20456 HIGH 7.8 goverlan client_agent Goverlan Reach Console before 9.50, Goverlan Reach Server before 3.50, and Goverlan Client Agent before 9.20.50 have an Untrusted Search Path that leads to Command Injection and Local Privilege Escalation via DLL hijacking. 0.7%
CVE-2017-9077 HIGH 7.8 linux linux_kernel The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CVE 0.7%
CVE-2015-0756 MED 6.1 cisco wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.4(1.1) allow remote attackers to cause a denial of service (wireless-networking outage) via crafted TCP traffic on the local network, aka Bug ID CSCug67104. 0.7%
CVE-2012-1366 MED 6.1 cisco asr_1001 Cisco IOS before 15.1(1)SY on ASR 1000 devices, when Multicast Listener Discovery (MLD) tracking is enabled for IPv6, allows remote attackers to cause a denial of service (device reload) via crafted MLD packets, aka Bug ID CSCtz28544. 0.7%
CVE-2005-0916 LOW 2.1 linux linux_kernel AIO in the Linux kernel 2.6.11 on the PPC64 or IA64 architectures with CONFIG_HUGETLB_PAGE enabled allows local users to cause a denial of service (system panic) via a process that executes the io_queue_init function but exits without running io_queue_release, 0.7%
CVE-2026-47430 HIGH 7.5 apache cordova_inappbrowser ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web content loaded inside t 0.7%
CVE-2024-26736 HIGH 8.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: afs: Increase buffer size in afs_update_volume_status() The max length of volume->vid value is 20 characters. So increase idbuf[] size up to 24 to avoid overflow. Found by Linux Verificatio 0.7%