57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-39018 | MED 4.3 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726. | 0.6% | — |
| CVE-2021-1507 | MED 6.4 | cisco sd-wan_vmanage A vulnerability in an API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the application web-based interface. This vulnerability exists because the API does | 0.6% | — |
| CVE-2020-29013 | MED 5.4 | fortinet fortisandbox An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests. | 0.6% | — |
| CVE-2019-17052 | LOW 3.3 | canonical ubuntu_linux ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768. | 0.6% | — |
| CVE-2014-9803 | HIGH 7.8 | google android arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android | 0.6% | — |
| CVE-2011-4847 | HIGH 7.5 | parallels parallels_plesk_panel SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/. | 0.6% | — |
| CVE-2005-4825 | MED 5.7 | cisco network_admission_control_manager_and_server_system_software Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP script | 0.6% | — |
| CVE-2026-61486 | CRIT 9.8 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find a | 0.6% | — |
| CVE-2026-50524 | HIGH 7.5 | microsoft .net Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2024-43508 | MED 5.5 | microsoft windows_11_22h2 Windows Graphics Component Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-43500 | MED 5.5 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-41694 | MED 4.9 | f5 big-ip_access_policy_manager In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can c | 0.6% | — |
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-22050 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21862 | HIGH 7.0 | microsoft windows_10 Windows Application Model Core API Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21859 | HIGH 7.0 | microsoft windows_10 Windows Accounts Control Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-3043 | HIGH 7.5 | paloaltonetworks prisma_cloud A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web inte | 0.6% | — |
| CVE-2020-27729 | MED 6.1 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to build an open redirect URI. | 0.6% | — |
| CVE-2019-1893 | HIGH 7.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient i | 0.6% | — |
| CVE-2026-62822 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-24304 | CRIT 9.9 | microsoft azure_resource_manager Improper access control in Azure Resource Manager allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-24281 | HIGH 7.4 | apache zookeeper Hostname verification in Apache ZooKeeper ZKTrustManager falls back to reverse DNS (PTR) when IP SAN validation fails, allowing attackers who control or spoof PTR records to impersonate ZooKeeper servers or clients with a valid certificate for the PTR name. It | 0.6% | — |
| CVE-2026-0279 | MED 6.1 | paloaltonetworks pan-os Multiple cross site scripting vulnerabilities in the User-ID™ Authentication Portal (aka Captive Portal) service, GlobalProtect™ gateway/portal features and Clientless VPN of Palo Alto Networks PAN-OS® software enables a malicious unauthenticated user to store | 0.6% | — |
| CVE-2025-29979 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-20127 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an aut | 0.6% | — |