57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1682 | HIGH 7.0 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-0258 | MED 5.9 | juniper junos A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these | 0.6% | — |
| CVE-2018-13375 | MED 6.1 | fortinet fortianalyzer An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is execu | 0.6% | — |
| CVE-2018-0054 | MED 6.5 | juniper junos On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface (fxp0) can cause egress interface congestion, resulting in routing protocol packet drops, such as BGP, leading to peering fl | 0.6% | — |
| CVE-2015-9281 | MED 6.1 | sas web_infrastructure_platform Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. | 0.6% | — |
| CVE-2014-3403 | MED 5.0 | cisco ios_xe The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spoof devices via crafted messages, aka Bug ID CSCuq22647. | 0.6% | — |
| CVE-2013-1189 | MED 5.7 | cisco ubr10012 Cisco Universal Broadband (aka uBR) 10000 series routers, when an IPv4/IPv6 dual-stack modem is used, allow remote attackers to cause a denial of service (routing-engine reload) via unspecified changes to IP address assignments, aka Bug ID CSCue15313. | 0.6% | — |
| CVE-2011-0588 | MED 6.9 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than | 0.6% | — |
| CVE-2011-0570 | MED 6.9 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than | 0.6% | — |
| CVE-2003-0462 | LOW 1.2 | linux linux_kernel A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash). | 0.6% | — |
| CVE-2026-69679 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-69637 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-50632 | HIGH 8.1 | apache cxf A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users | 0.6% | — |
| CVE-2026-48895 | HIGH 7.2 | apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3 | 0.6% | — |
| CVE-2026-44913 | HIGH 7.2 | apache nifi Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potent | 0.6% | — |
| CVE-2026-21529 | MED 5.7 | microsoft azure_hdinsight Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2024-43513 | MED 6.4 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-42110 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx() The following is emitted when using idxd (DSA) dmanegine as the data mover for ntb_transport that ntb_netde | 0.6% | — |
| CVE-2024-37973 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-28916 | HIGH 8.8 | microsoft xbox_gaming_services Xbox Gaming Services Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-26826 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data re-injection from stale subflow When the MPTCP PM detects that a subflow is stale, all the packet scheduler must re-inject all the mptcp-level unacked data. To avoid acquirin | 0.6% | — |
| CVE-2023-52834 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: atl1c: Work around the DMA RX overflow issue This is based on alx driver commit 881d0327db37 ("net: alx: Work around the DMA RX overflow issue"). The alx and atl1c drivers had RX overflow e | 0.6% | — |
| CVE-2022-20677 | MED 5.5 | cisco ios Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 0.6% | — |
| CVE-2021-33784 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33759 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.6% | — |