57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-32414 | MED 5.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c. | 0.7% | — |
| CVE-2022-31307 | MED 5.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c. | 0.7% | — |
| CVE-2022-31306 | MED 5.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c. | 0.7% | — |
| CVE-2021-31364 | MED 5.9 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated networ | 0.7% | — |
| CVE-2020-8648 | HIGH 7.1 | broadcom brocade_fabric_operating_system_firmware There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. | 0.7% | — |
| CVE-2019-20362 | HIGH 7.8 | teradici pcoip_client In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file. | 0.7% | — |
| CVE-2018-15373 | HIGH 7.4 | cisco ios A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) co | 0.7% | — |
| CVE-2014-0205 | MED 6.9 | linux linux_kernel The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain | 0.7% | — |
| CVE-2013-2930 | LOW 3.6 | linux linux_kernel The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application. | 0.7% | — |
| CVE-2010-2506 | LOW 2.9 | cisco linksys_firmware Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter. | 0.7% | — |
| CVE-2026-56171 | HIGH 7.1 | microsoft remote_desktop_web_client Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-44914 | HIGH 7.2 | apache nifi Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required | 0.7% | — |
| CVE-2024-53066 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfs: Fix KMSAN warning in decode_getfattr_attrs() Fix the following KMSAN warning: CPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B Tainted: [B]=BAD_PAGE Hardware name: QEMU Standard PC (Q3 | 0.7% | — |
| CVE-2024-30471 | LOW 3.7 | apache streampipes Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is registered, | 0.7% | — |
| CVE-2023-20866 | MED 6.5 | vmware spring_session In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application i | 0.7% | — |
| CVE-2022-27502 | HIGH 7.8 | realvnc vnc_server RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. | 0.7% | — |
| CVE-2022-22245 | MED 4.3 | juniper junos A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file | 0.7% | — |
| CVE-2022-22157 | HIGH 7.2 | juniper junos A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on | 0.7% | — |
| CVE-2022-21869 | HIGH 7.0 | microsoft windows_10 Clipboard User Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21861 | HIGH 7.0 | microsoft windows_10 Task Flow Data Engine Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-22543 | HIGH 7.8 | debian debian_linux An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to r | 0.7% | — |
| CVE-2016-4928 | HIGH 8.8 | juniper junos_space Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space. | 0.7% | — |
| CVE-2026-46457 | HIGH 7.5 | apache camel Improper Input Validation vulnerability in Apache Camel NATS component. The camel-nats component maps inbound NATS message headers into the Camel Exchange but defaulted its headerFilterStrategy to a bare new DefaultHeaderFilterStrategy() with no inbound rules | 0.7% | — |
| CVE-2026-33821 | HIGH 7.7 | microsoft dynamics_365_customer_insights Improper privilege management in Microsoft Dynamics 365 Customer Insights allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-23249 | HIGH 7.6 | nvidia nemo NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering. | 0.7% | — |