57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-21515 | CRIT 9.9 | microsoft azure_iot_central Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2023-49322 | HIGH 7.5 | f-secure atlant Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSec | 0.7% | — |
| CVE-2023-47264 | HIGH 7.5 | withsecure atlant Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure E | 0.7% | — |
| CVE-2023-47263 | HIGH 7.5 | withsecure atlant Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoi | 0.7% | — |
| CVE-2023-40683 | HIGH 8.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to by | 0.7% | — |
| CVE-2022-43946 | HIGH 7.5 | fortinet forticlient Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on | 0.7% | — |
| CVE-2022-34844 | MED 5.9 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1 and 15.1.x before 15.1.6.1, and all versions of BIG-IQ 8.x, when the Data Plane Development Kit (DPDK)/Elastic Network Adapter (ENA) driver is used with BIG-IP or BIG-IQ on Amazon Web Services (AWS) systems, undisclose | 0.7% | — |
| CVE-2021-43231 | HIGH 7.8 | microsoft windows_10 Windows NTFS Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40441 | HIGH 7.8 | microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26582 | MED 6.1 | hp icewall_sso_dgfw A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). | 0.7% | — |
| CVE-2009-0676 | LOW 2.1 | linux linux_kernel The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request. | 0.7% | — |
| CVE-2008-3889 | LOW 2.1 | postfix postfix Postfix 2.4 before 2.4.9, 2.5 before 2.5.5, and 2.6 before 2.6-20080902, when used with the Linux 2.6 kernel, leaks epoll file descriptors during execution of "non-Postfix" commands, which allows local users to cause a denial of service (application slowdown o | 0.7% | — |
| CVE-2002-0954 | HIGH 7.5 | cisco pix_firewall The encryption algorithms for enable and passwd commands on Cisco PIX Firewall can be executed quickly due to a limited number of rounds, which make it easier for an attacker to decrypt the passwords using brute force techniques. | 0.7% | — |
| CVE-2026-65099 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of | 0.7% | — |
| CVE-2026-65096 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosur | 0.7% | — |
| CVE-2026-65090 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial | 0.7% | — |
| CVE-2026-65089 | HIGH 7.8 | nvidia nemoclaw NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and | 0.7% | — |
| CVE-2025-26685 | MED 6.5 | microsoft defender_for_identity Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. | 0.7% | — |
| CVE-2025-26643 | MED 5.4 | microsoft edge_chromium The UI performs the wrong action in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2025-24082 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-21396 | HIGH 8.2 | microsoft account Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-36448 | HIGH 7.3 | apache iotdb_workbench ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users a | 0.7% | — |
| CVE-2024-20681 | HIGH 7.8 | microsoft windows_10_21h2 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-41151 | HIGH 7.5 | softing opc An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing. | 0.7% | — |
| CVE-2023-24947 | HIGH 8.8 | microsoft windows_10_1607 Windows Bluetooth Driver Remote Code Execution Vulnerability | 0.7% | — |