58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.127 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-45720 | HIGH 8.2 | apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra | 0.6% | — |
| CVE-2024-28919 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-20669 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-52881 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: do not accept ACK of bytes we never sent This patch is based on a detailed report and ideas from Yepeng Pan and Christian Rossow. ACK seq validation is currently following RFC 5961 5.2 | 0.6% | — |
| CVE-2023-47148 | MED 5.3 | ibm spectrum_protect_plus IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: | 0.6% | — |
| CVE-2023-21572 | MED 6.5 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.6% | — |
| CVE-2022-49110 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter: conntrack: collect all entries in one cycle") conntrack gc was changed to run every 2 minutes. On systems | 0.6% | — |
| CVE-2022-20939 | MED 4.3 | cisco smart_software_manager_on-prem A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to inadequate protection of sensitive user | 0.6% | — |
| CVE-2021-34764 | MED 4.8 | cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabiliti | 0.6% | — |
| CVE-2021-33656 | MED 6.8 | debian debian_linux When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. | 0.6% | — |
| CVE-2021-31820 | HIGH 7.5 | octopus octopus_server In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. | 0.6% | — |
| CVE-2021-22117 | HIGH 7.8 | broadcom rabbitmq_server RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins. | 0.6% | — |
| CVE-2019-1649 | MED 6.7 | cisco 15454-m-wse-k9_firmware A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability af | 0.6% | — |
| CVE-2019-1567 | MED 5.4 | paloaltonetworks expedition_migration_tool The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings. | 0.6% | — |
| CVE-2018-0021 | HIGH 8.8 | juniper junos If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CAK) key are not configured, all remaining digits will be auto-configured to 0. Hence, Juniper devices configured with short MacSec keys are a | 0.6% | — |
| CVE-2009-3725 | HIGH 7.2 | canonical ubuntu_linux The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and | 0.6% | — |
| CVE-2025-59282 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-49696 | HIGH 8.4 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21184 | HIGH 7.0 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.6% | — |
| CVE-2024-56662 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] B | 0.6% | — |
| CVE-2024-38086 | MED 6.4 | microsoft azure_kinect_software_development_kit Azure Kinect SDK Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-36719 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-36408 | HIGH 7.8 | microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-23482 | MED 5.4 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim | 0.6% | — |
| CVE-2023-22637 | MED 6.5 | fortinet fortinac An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Mana | 0.6% | — |