58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-22400 | HIGH 7.5 | juniper junos_os_evolved An Uncontrolled Resource Consumption vulnerability in the PFE management daemon (evo-pfemand) of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to cause an FPC crash leading to a Denial of Service (DoS). When a specific SNM | 0.6% | — |
| CVE-2023-22394 | HIGH 7.5 | juniper junos An Improper Handling of Unexpected Data Type vulnerability in the handling of SIP calls in Juniper Networks Junos OS on SRX Series and MX Series platforms allows an attacker to cause a memory leak leading to Denial of Services (DoS). This issue occurs on all M | 0.6% | — |
| CVE-2023-22393 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to cause Routing Protocol Daemon (RPD) crash by sending a BGP route with invalid next-hop resulti | 0.6% | — |
| CVE-2023-22391 | HIGH 7.5 | juniper junos A vulnerability in class-of-service (CoS) queue management in Juniper Networks Junos OS on the ACX2K Series devices allows an unauthenticated network-based attacker to cause a Denial of Service (DoS). Specific packets are being incorrectly routed to a queue us | 0.6% | — |
| CVE-2022-35792 | HIGH 7.8 | microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-20818 | HIGH 7.8 | cisco sd-wan Multiple vulnerabilities in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. These vulnerabilities are due to improper access controls on commands within the application CLI. An attacker could exploit t | 0.6% | — |
| CVE-2021-47232 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix Use-after-Free, hold skb ref while in use This patch fixes a Use-after-Free found by the syzbot. The problem is that a skb is taken from the per-session skb queue, without i | 0.6% | — |
| CVE-2021-3739 | HIGH 7.1 | fedoraproject fedora A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. T | 0.6% | — |
| CVE-2021-34738 | MED 6.1 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulnerabili | 0.6% | — |
| CVE-2021-29849 | MED 6.1 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 0.6% | — |
| CVE-2021-28440 | HIGH 7.0 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-24020 | HIGH 7.5 | fortinet fortimail A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allows bypass of signatur | 0.6% | — |
| CVE-2021-1458 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabili | 0.6% | — |
| CVE-2021-1457 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabili | 0.6% | — |
| CVE-2021-1456 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabili | 0.6% | — |
| CVE-2021-1455 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabili | 0.6% | — |
| CVE-2019-14743 | MED 6.6 | valvesoftware steam_client In Valve Steam Client for Windows through 2019-08-07, HKLM\SOFTWARE\Wow6432Node\Valve\Steam has explicit "Full control" for the Users group, which allows local users to gain NT AUTHORITY\SYSTEM access. | 0.6% | — |
| CVE-2008-4302 | MED 5.5 | debian debian_linux fs/splice.c in the splice subsystem in the Linux kernel before 2.6.22.2 does not properly handle a failure of the add_to_page_cache_lru function, and subsequently attempts to unlock a page that was not locked, which allows local users to cause a denial of serv | 0.6% | — |
| CVE-2026-45816 | HIGH 7.5 | apache nimble NULL Pointer Dereference vulnerability in Apache NimBLE in LE Long Term Key Request event. This requires disabled asserts (otherwise assert would trigger before NULL dereference) and bogus (or misbehaving) controller, thus severity is low. This issue affects | 0.6% | — |
| CVE-2026-23980 | MED 6.5 | apache superset Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affec | 0.6% | — |
| CVE-2025-29976 | HIGH 7.8 | microsoft sharepoint_server Improper privilege management in Microsoft Office SharePoint allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-5692 | MED 6.5 | mozilla firefox On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows opera | 0.6% | — |
| CVE-2024-49043 | HIGH 7.8 | microsoft sql_server_2016 Microsoft.SqlServer.XEvent.Configuration.dll Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2024-43457 | HIGH 7.8 | microsoft windows_11_24h2 Windows Setup and Deployment Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-41177 | MED 6.1 | apache zeppelin Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | 0.6% | — |