57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1158 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0.7% | — |
| CVE-2021-1151 | MED 4.8 | cisco application_extension_platform Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. The vu | 0.7% | — |
| CVE-2020-3460 | MED 6.1 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because t | 0.7% | — |
| CVE-2019-1952 | MED 6.7 | cisco enterprise_nfv_infrastructure_software A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to overwrite or read arbitrary files. The attacker would need valid administrator privilege-level credentials. This vulnerability is | 0.7% | — |
| CVE-2017-0331 | HIGH 7.8 | google android An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom | 0.7% | — |
| CVE-2015-0710 | MED 6.1 | cisco ios_xe The Overlay Transport Virtualization (OTV) implementation in Cisco IOS XE 3.10S allows remote attackers to cause a denial of service (device reload) via a series of packets that are considered oversized and trigger improper fragmentation handling, aka Bug IDs | 0.7% | — |
| CVE-2013-7421 | LOW 2.1 | canonical ubuntu_linux The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644. | 0.7% | — |
| CVE-2010-2240 | HIGH 7.2 | linux linux_kernel The do_anonymous_page function in mm/memory.c in the Linux kernel before 2.6.27.52, 2.6.32.x before 2.6.32.19, 2.6.34.x before 2.6.34.4, and 2.6.35.x before 2.6.35.2 does not properly separate the stack and the heap, which allows context-dependent attackers to | 0.7% | — |
| CVE-2001-0317 | LOW 3.7 | linux linux_kernel Race condition in ptrace in Linux kernel 2.4 and 2.2 allows local users to gain privileges by using ptrace to track and modify a running setuid process. | 0.7% | — |
| CVE-2026-29145 | CRIT 9.1 | apache tomcat CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0 | 0.7% | — |
| CVE-2024-45324 | HIGH 7.2 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b | 0.7% | — |
| CVE-2024-28920 | HIGH 7.8 | microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-26582 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: tls: fix use-after-free with partial reads and async decrypt tls_decrypt_sg doesn't take a reference on the pages from clear_skb, so the put_page() in tls_decrypt_done releases them, an | 0.7% | — |
| CVE-2024-20458 | HIGH 8.2 | cisco ata_191_firmware A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to view or delete the configuration or change the firmware on an affected device. This vulnerabil | 0.7% | — |
| CVE-2023-6931 | HIGH 7.8 | debian debian_linux A heap out-of-bounds write vulnerability in the Linux kernel's Performance Events system component can be exploited to achieve local privilege escalation. A perf_event's read_size can overflow, leading to an heap out-of-bounds increment or write in perf_rea | 0.7% | — |
| CVE-2023-36898 | HIGH 7.8 | microsoft windows_11_21h2 Tablet Windows User Interface Application Core Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-31488 | CRIT 9.8 | cisco ironport_email_security_appliance Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbit | 0.7% | — |
| CVE-2022-24466 | MED 4.1 | microsoft windows_10 Windows Hyper-V Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2020-0785 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows User Profile Service (ProfSvc) improperly handles symlinks, aka 'Windows User Profile Service Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2017-12281 | HIGH 7.5 | cisco aironet_1800_firmware A vulnerability in the implementation of Protected Extensible Authentication Protocol (PEAP) functionality for standalone configurations of Cisco Aironet 1800, 2800, and 3800 Series Access Points could allow an unauthenticated, adjacent attacker to bypass auth | 0.7% | — |
| CVE-2026-68784 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-68781 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-67389 | MED 6.5 | microsoft sql_server_2022 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-67386 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-66816 | MED 6.5 | microsoft sql_server_2022 Insufficient logging in SQL Server allows an authorized attacker to bypass a security feature over a network. | 0.7% | — |