IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-43516 HIGH 7.8 microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability 0.6%
CVE-2024-38820 LOW 3.1 vmware spring_framework The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected. 0.6%
CVE-2024-21364 CRIT 9.3 microsoft azure_site_recovery Microsoft Azure Site Recovery Elevation of Privilege Vulnerability 0.6%
CVE-2023-44154 HIGH 8.1 acronis cyber_protect Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. 0.6%
CVE-2023-28291 HIGH 8.4 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 0.6%
CVE-2023-23398 HIGH 7.1 microsoft 365_apps Microsoft Excel Spoofing Vulnerability 0.6%
CVE-2022-38170 MED 4.7 apache airflow In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users t 0.6%
CVE-2021-42300 MED 6.0 microsoft azure_sphere Azure Sphere Tampering Vulnerability 0.6%
CVE-2020-7053 HIGH 7.8 linux linux_kernel In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c. This is related to i915_ 0.6%
CVE-2020-3589 MED 4.8 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. 0.6%
CVE-2020-3491 MED 5.5 cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct a cross-site scripting (XSS) attack against a user of the interface on an aff 0.6%
CVE-2020-3464 MED 4.8 cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists b 0.6%
CVE-2020-26083 MED 4.8 cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vuln 0.6%
CVE-2020-10732 LOW 3.3 canonical ubuntu_linux A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. 0.6%
CVE-2016-6375 MED 5.3 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and the 0.6%
CVE-2004-2013 HIGH 7.8 linux linux_kernel Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory. 0.6%
CVE-2026-81381 MED 6.5 microsoft visual_studio_code Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2025-50213 CRIT 9.8 apache apache-airflow-providers-snowflake Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow Providers Snowflake. This issue affects Apache Airflow Providers Snowflake: before 6.4.0. Sanitation of table and stage parameters were ad 0.6%
CVE-2025-32702 HIGH 7.8 microsoft visual_studio_2019 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally. 0.6%
CVE-2024-49072 HIGH 7.8 microsoft windows_10_1507 Windows Task Scheduler Elevation of Privilege Vulnerability 0.6%
CVE-2024-20470 HIGH 7.2 cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. In order to exploit this 0.6%
CVE-2024-20429 MED 6.5 cisco asyncos A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary system commands on an affected device. This vulnerability is due to insufficient input validat 0.6%
CVE-2023-29163 HIGH 7.5 f5 big-ip_access_policy_manager When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.6%
CVE-2023-22411 HIGH 7.5 juniper junos An Out-of-Bounds Write vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS). On SRX Series devices using Unified Policies with IPv6, when a specific IPv6 0.6%
CVE-2023-22401 HIGH 7.5 juniper junos An Improper Validation of Array Index vulnerability in the Advanced Forwarding Toolkit Manager daemon (aftmand) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). On the PTX10 0.6%