57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2002-0499 | LOW 2.1 | linux linux_kernel The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. | 1.0% | — |
| CVE-2025-50171 | CRIT 9.1 | microsoft windows_server_2022 Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2024-54181 | HIGH 7.2 | ibm websphere_automation IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system. | 1.0% | — |
| CVE-2024-26592 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix UAF issue in ksmbd_tcp_new_connection() The race is between the handling of a new TCP connection and its disconnection. It leads to UAF on `struct tcp_transport` in ksmbd_tcp_new_ | 1.0% | — |
| CVE-2023-28283 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-22996 | HIGH 7.5 | f5 big-iq_centralized_management On all 7.x versions (fixed in 8.0.0), when set up for auto failover, a BIG-IQ Data Collection Device (DCD) cluster member that receives an undisclosed message may cause the corosync process to abort. This behavior may lead to a denial-of-service (DoS) and impa | 1.0% | — |
| CVE-2019-0036 | CRIT 9.8 | juniper junos When configuring a stateless firewall filter in Junos OS, terms named using the format "internal-n" (e.g. "internal-1", "internal-2", etc.) are silently ignored. No warning is issued during configuration, and the config is committed without error, but the filt | 1.0% | — |
| CVE-2018-0039 | MED 6.5 | juniper contrail_service_orchestration Juniper Networks Contrail Service Orchestration releases prior to 4.0.0 have Grafana service enabled by default with hardcoded credentials. These credentials allow network based attackers unauthorized access to information stored in Grafana or exploit other we | 1.0% | — |
| CVE-2017-2334 | HIGH 7.5 | juniper northstar_controller An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby stealing authentic credentials from encrypt | 1.0% | — |
| CVE-2015-0661 | MED 4.0 | cisco ios_xr The SNMPv2 implementation in Cisco IOS XR allows remote authenticated users to cause a denial of service (snmpd daemon reload) via a malformed SNMP packet, aka Bug ID CSCur25858. | 1.0% | — |
| CVE-2012-3096 | MED 4.0 | cisco unity_connection Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132. | 1.0% | — |
| CVE-2026-8476 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without validation, | 1.0% | — |
| CVE-2026-56190 | CRIT 9.8 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-56159 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-55010 | CRIT 9.8 | microsoft minecraft_bedrock_dedicated_server Heap-based buffer overflow in Minecraft Bedrock Dedicated Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50518 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50447 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Message Queuing allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-49172 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-42990 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in SQL Server ODBC driver allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-52699 | MED 5.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: sysv: don't call sb_bread() with pointers_lock held syzbot is reporting sleep in atomic context in SysV filesystem [1], for sb_bread() is called with rw_spinlock held. A "write_lock(&pointe | 1.0% | — |
| CVE-2022-20851 | MED 5.5 | cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this v | 1.0% | — |
| CVE-2021-34766 | MED 5.4 | cisco smart_software_manager_on-prem A vulnerability in the web UI of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges and create, read, update, or delete records and settings in multiple functions. This vulnerability is due to | 1.0% | — |
| CVE-2021-33760 | MED 5.5 | microsoft windows_10 Media Foundation Information Disclosure Vulnerability | 1.0% | — |
| CVE-2021-20508 | MED 4.3 | ibm security_secret_server IBM Security Secret Server up to 11.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 199322 | 1.0% | — |
| CVE-2020-26079 | MED 4.9 | cisco iot_field_network_director A vulnerability in the web UI of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to obtain hashes of user passwords on an affected device. The vulnerability is due to insufficient protection of user credentials. An attacker | 1.0% | — |