58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-47849 | HIGH 8.8 | apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation | 0.6% | — |
| CVE-2025-47713 | HIGH 8.8 | apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricte | 0.6% | — |
| CVE-2024-26009 | HIGH 8.1 | fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, Fo | 0.6% | — |
| CVE-2023-33307 | MED 6.5 | fortinet fortios A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of sslvpn service via specifically crafted request in network parameter. | 0.6% | — |
| CVE-2021-34760 | MED 4.8 | cisco telepresence_management_suite A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due | 0.6% | — |
| CVE-2021-32600 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS CLI 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2.9, 6.0.x and 5.6.x may allow a local and authenticated user assigned to a specific VDOM to retrieve other VDOMs information | 0.6% | — |
| CVE-2021-1383 | MED 6.0 | cisco ios_xe Multiple vulnerabilities in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to access the underlying operating system with root privileges. These vulnerabilities are due to insufficient input validation of certain CLI comma | 0.6% | — |
| CVE-2019-1857 | MED 6.1 | cisco hx220c_af_m5_firmware A vulnerability in the web-based management interface of Cisco HyperFlex HX-Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected system. The vulnerability is d | 0.6% | — |
| CVE-2018-15316 | MED 5.5 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 13.0.0-13.1.1.1, APM Client 7.1.5-7.1.6, and/or Edge Client 7101-7160, the BIG-IP APM Edge Client component loads the policy library with user permission and bypassing the endpoint checks. | 0.6% | — |
| CVE-2026-43011 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/x25: Fix potential double free of skb When alloc_skb fails in x25_queue_rx_frame it calls kfree_skb(skb) at line 48 and returns 1 (error). This error propagates back through the call cha | 0.6% | — |
| CVE-2024-46858 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: Fix uaf in __timer_delete_sync There are two paths to access mptcp_pm_del_add_timer, result in a race condition: CPU1 CPU2 ==== ==== | 0.6% | — |
| CVE-2024-27066 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: virtio: packed: fix unmap leak for indirect desc table When use_dma_api and premapped are true, then the do_unmap is false. Because the do_unmap is false, vring_unmap_extra_packed is not ca | 0.6% | — |
| CVE-2023-36008 | MED 6.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21759 | LOW 3.3 | microsoft windows_10 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2021-46948 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sfc: farch: fix TX queue lookup in TX event handling We're starting from a TXQ label, not a TXQ type, so efx_channel_get_tx_queue() is inappropriate (and could return NULL, leading to pani | 0.6% | — |
| CVE-2014-0351 | MED 5.4 | fortinet fortios The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphersuites, which makes it easier for man-in-the-middle attackers to obtain sensitive information or interfere wit | 0.6% | — |
| CVE-2026-65182 | CRIT 9.1 | apache tomcat Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: | 0.6% | — |
| CVE-2026-45361 | HIGH 8.1 | apache apache-airflow-providers-google Apache Airflow providers-google's `ComputeEngineSSHHook` disables SSH host-key verification by default, exposing SSH traffic between an Airflow worker and a Compute Engine VM to in-path network attackers who can intercept or modify the session. Users are advis | 0.6% | — |
| CVE-2025-53795 | CRIT 9.1 | microsoft pc_manager Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2025-4613 | HIGH 8.8 | google web_designer Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template | 0.6% | — |
| CVE-2025-20344 | MED 6.5 | cisco nexus_dashboard A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. This vulnerability is due to insufficient validation of the contents of a ba | 0.6% | — |
| CVE-2024-23307 | MED 4.4 | linux linux_kernel Integer Overflow or Wraparound vulnerability in Linux Linux kernel kernel on Linux, x86, ARM (md, raid, raid5 modules) allows Forced Integer Overflow. | 0.6% | — |
| CVE-2024-20393 | HIGH 8.8 | cisco rv340_dual_wan_gigabit_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability exists | 0.6% | — |
| CVE-2023-52801 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: iommufd: Fix missing update of domains_itree after splitting iopt_area In iopt_area_split(), if the original iopt_area has filled a domain and is linked to domains_itree, pages_nodes have to | 0.6% | — |
| CVE-2023-38161 | HIGH 7.8 | microsoft windows_10_1507 Windows GDI Elevation of Privilege Vulnerability | 0.6% | — |