IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2016-2067 HIGH 7.8 google android drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows atta 0.7%
CVE-2014-1210 MED 5.8 vmware vsphere_client VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. 0.7%
CVE-2026-62910 HIGH 7.2 microsoft exchange_server Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-53421 CRIT 9.8 apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Gro 0.7%
CVE-2024-24778 MED 6.5 apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe 0.7%
CVE-2023-28222 HIGH 7.1 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2023-20081 MED 6.8 cisco adaptive_security_appliance_software A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a 0.7%
CVE-2023-20057 NONE 0.0 cisco asyncos A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improp 0.7%
CVE-2022-21912 HIGH 7.8 microsoft windows_10 DirectX Graphics Kernel Remote Code Execution Vulnerability 0.7%
CVE-2022-21875 HIGH 7.0 microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability 0.7%
CVE-2022-21873 HIGH 7.0 microsoft windows_10 Tile Data Repository Elevation of Privilege Vulnerability 0.7%
CVE-2022-21872 HIGH 7.0 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.7%
CVE-2022-21870 HIGH 7.0 microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability 0.7%
CVE-2022-20952 MED 5.3 cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a 0.7%
CVE-2019-7222 MED 5.5 canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. 0.7%
CVE-2018-0408 MED 5.4 cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management 0.7%
CVE-2018-0407 MED 5.4 cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web-based management 0.7%
CVE-2014-7991 MED 4.3 cisco unified_communications_manager The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices 0.7%
CVE-2013-0346 LOW 2.1 apache tomcat Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensi 0.7%
CVE-2026-63041 HIGH 8.8 apache apisix Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitis 0.7%
CVE-2026-45860 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections ar 0.7%
CVE-2026-28779 HIGH 7.5 apache airflow Apache Airflow versions 3.1.0 through 3.1.7 session token (_token) in cookies is set to path=/ regardless of the configured [webserver] base_url or [api] base_url. This allows any application co-hosted under the same domain to capture valid Airflow session tok 0.7%
CVE-2025-21384 HIGH 8.3 microsoft azure_health_bot An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network. 0.7%
CVE-2023-52628 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nftables: exthdr: fix 4-byte stack OOB write If priv->len is a multiple of 4, then dst[len / 4] can write past the destination array which leads to stack corruption. This constru 0.7%
CVE-2023-36705 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0.7%