57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-1226 | MED 6.1 | cisco nexus_7000 The Ethernet frame-forwarding implementation in Cisco NX-OS on Nexus 7000 devices allows remote attackers to cause a denial of service (forwarding loop and service outage) via a crafted frame, aka Bug ID CSCug47098. | 0.7% | — |
| CVE-2026-42402 | HIGH 7.5 | apache neethi Apache Neethi is vulnerable to a Denial of Service attack through algorithmic complexity in policy normalization. Specially crafted WS-Policy documents can trigger an exponential Cartesian cross-product expansion during the normalization process, causing unbou | 0.7% | — |
| CVE-2026-33929 | MED 4.3 | apache pdfbox Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache PDFBox Examples. This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.36, from 3.0.0 through 3.0.7. Users are re | 0.7% | — |
| CVE-2026-33109 | CRIT 9.9 | microsoft azure_managed_instance_for_apache_cassandra Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-32175 | MED 4.3 | microsoft .net A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker | 0.7% | — |
| CVE-2025-62207 | HIGH 8.6 | microsoft azure_monitor Azure Monitor Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21188 | MED 6.0 | microsoft azure_network_watcher Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-35277 | HIGH 8.6 | fortinet fortimanager A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the | 0.7% | — |
| CVE-2024-30329 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerabil | 0.7% | — |
| CVE-2024-30030 | HIGH 7.8 | microsoft windows_server_2008 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-30028 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-29992 | MED 5.5 | microsoft azure_identity_library_for_.net Azure Identity Library for .NET Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-26880 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: dm: call the resume method on internal suspend There is this reported crash when experimenting with the lvm2 testsuite. The list corruption is caused by the fact that the postsuspend and res | 0.7% | — |
| CVE-2024-20339 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the TLS processing feature of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerabi | 0.7% | — |
| CVE-2023-38131 | MED 6.5 | intel unison_software Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access. | 0.7% | — |
| CVE-2022-33675 | HIGH 7.8 | microsoft azure_site_recovery_vmware_to_azure Azure Site Recovery Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-27363 | MED 4.4 | debian debian_linux An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unpr | 0.7% | — |
| CVE-2021-26864 | HIGH 8.4 | microsoft windows_10 Windows Virtual Registry Provider Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-16989 | MED 5.4 | microsoft azure_sphere Azure Sphere Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-12657 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body. | 0.7% | — |
| CVE-2020-1002 | HIGH 7.1 | microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu | 0.7% | — |
| CVE-2014-0737 | MED 4.3 | cisco unified_ip_phone_7960g The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795. | 0.7% | — |
| CVE-2010-3849 | MED 4.7 | canonical ubuntu_linux The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value | 0.7% | — |
| CVE-2026-60005 | HIGH 8.2 | f5 nginx_gateway_fabric NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause | 0.7% | — |
| CVE-2026-22153 | HIGH 8.1 | fortinet fortios An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is confi | 0.7% | — |