57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-29057 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2024-22275 | MED 4.9 | vmware cloud_foundation The vCenter Server contains a partial file read vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to partially read arbitrary files containing sensitive data. | 1.0% | — |
| CVE-2023-37936 | CRIT 9.8 | fortinet fortiswitch A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via cr | 1.0% | — |
| CVE-2023-36393 | HIGH 7.8 | microsoft windows_10_1507 Windows User Interface Application Core Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-43869 | MED 6.5 | ibm elastic_storage_system IBM Spectrum Scale (5.1.0.0 through 5.1.2.8 and 5.1.3.0 through 5.1.5.1) and IBM Elastic Storage System (6.1.0.0 through 6.1.2.4 and 6.1.3.0 through 6.1.4.1) could allow an authenticated user to cause a denial of service through the GUI using a format string a | 1.0% | — |
| CVE-2022-20808 | HIGH 7.7 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous dev | 1.0% | — |
| CVE-2021-22038 | HIGH 8.8 | vmware installbuilder On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict a | 1.0% | — |
| CVE-2021-22003 | HIGH 7.5 | vmware cloud_foundation VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based | 1.0% | — |
| CVE-2020-8950 | HIGH 7.8 | amd user_experience_program The AUEPLauncher service in Radeon AMD User Experience Program Launcher through 1.0.0.1 on Windows allows elevation of privilege by placing a crafted file in %PROGRAMDATA%\AMD\PPC\upload and then creating a symbolic link in %PROGRAMDATA%\AMD\PPC\temp that poin | 1.0% | — |
| CVE-2019-20096 | MED 5.5 | canonical ubuntu_linux In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b. | 1.0% | — |
| CVE-2019-17655 | MED 5.3 | fortinet fortios A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be | 1.0% | — |
| CVE-2019-10084 | HIGH 7.5 | apache impala In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions or queries via a specially-constructed request and thereby potentially bypass authorization and audit mechanisms | 1.0% | — |
| CVE-2011-1576 | MED 5.7 | linux linux_kernel The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to ca | 1.0% | — |
| CVE-2026-69723 | MED 5.7 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-64921 | HIGH 8.8 | microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-57982 | MED 6.5 | microsoft windows_10_1607 Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-54116 | MED 6.5 | microsoft sql_server_2025 Access of resource using incompatible type ('type confusion') in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-50468 | MED 6.5 | microsoft sql_server_2025 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2024-27347 | MED 5.3 | apache hugegraph-hubble Server-Side Request Forgery (SSRF) vulnerability in Apache HugeGraph-Hubble.This issue affects Apache HugeGraph-Hubble: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue. | 1.0% | — |
| CVE-2023-36020 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2022-30138 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-24499 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-23040 | HIGH 8.8 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a SQL injection vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. This issue is expos | 1.0% | — |
| CVE-2021-22976 | HIGH 7.5 | f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and ASM version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and all 12.1.x versions, when the BIG-IP ASM system processes WebSocket requests with JSON payloads, an unusually large number | 1.0% | — |
| CVE-2021-21552 | MED 5.2 | microsoft windows_10 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and | 1.0% | — |