57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-23781 | MED 6.4 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted XML | 0.7% | — |
| CVE-2022-22449 | MED 5.3 | ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM | 0.7% | — |
| CVE-2021-26426 | HIGH 7.0 | microsoft windows_10 Windows User Account Profile Picture Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-3507 | HIGH 8.8 | cisco 8000p_ip_camera_firmware Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabili | 0.7% | — |
| CVE-2020-11862 | HIGH 8.6 | opentext netiq_privileged_account_manager Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2. | 0.7% | — |
| CVE-2019-19039 | MED 5.5 | canonical ubuntu_linux __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS | 0.7% | — |
| CVE-2017-12339 | MED 5.7 | cisco lan_switch_software A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could ex | 0.7% | — |
| CVE-2005-0852 | LOW 2.1 | Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3. | 0.7% | — |
| CVE-2026-56649 | MED 5.9 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Network File System allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-48323 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to | 0.7% | — |
| CVE-2026-26145 | MED 4.8 | microsoft azure_synapse Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-56626 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write An offset from client could be a negative value, It could allows to write data outside the bounds of the allocated buffer. Note that | 0.7% | — |
| CVE-2024-38250 | HIGH 7.8 | microsoft 365_copilot Windows Graphics Component Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-20358 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the und | 0.7% | — |
| CVE-2023-32331 | HIGH 7.5 | ibm sterling_connect\ IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979. | 0.7% | — |
| CVE-2022-45432 | MED 5.3 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated search for devices. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could unauthenticated search for devices | 0.7% | — |
| CVE-2022-22204 | MED 5.3 | juniper junos An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network-based attacker to cause a partial Denial of Service | 0.7% | — |
| CVE-2022-21963 | MED 6.4 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-40447 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2011-2526 | MED 4.4 | apache tomcat Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or | 0.7% | — |
| CVE-2007-6192 | MED 4.3 | citrix netscaler The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-p | 0.7% | — |
| CVE-2025-26413 | HIGH 7.5 | apache kvrocks Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is out of range. This issue aff | 0.7% | — |
| CVE-2025-24067 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-24066 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-21341 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.7% | — |