58.254 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.254 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-33826 | HIGH 8.0 | microsoft windows_server_2012 Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-25689 | MED 6.5 | fortinet fortideceptor An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, | 0.5% | — |
| CVE-2025-61735 | HIGH 7.3 | apache kylin Server-Side Request Forgery (SSRF) vulnerability in Apache Kylin. This issue affects Apache Kylin: from 4.0.0 through 5.0.2. You are fine as long as the Kylin's system and project admin access is well protected. Users are recommended to upgrade to version 5. | 0.5% | — |
| CVE-2025-49722 | MED 5.7 | microsoft windows_10_1507 Uncontrolled resource consumption in Windows Print Spooler Components allows an authorized attacker to deny service over an adjacent network. | 0.5% | — |
| CVE-2023-41679 | HIGH 8.5 | fortinet fortimanager An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions may allow a remote and authenticated attacker with at least "device manag | 0.5% | — |
| CVE-2022-48629 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - ensure buffer for generate is completely filled The generate function in struct rng_alg expects that the destination buffer is completely filled if the function returns 0. | 0.5% | — |
| CVE-2022-30151 | HIGH 7.0 | microsoft windows_10 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-27505 | MED 6.1 | citrix sd-wan_1000_firmware Reflected cross site scripting (XSS) | 0.5% | — |
| CVE-2022-24549 | HIGH 7.8 | microsoft windows_10 Windows AppX Package Manager Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-22373 | MED 5.4 | ibm infosphere_information_server An improper validation vulnerability in IBM InfoSphere Information Server 11.7 Pack for SAP Apps and BW Packs may lead to creation of directories and files on the server file system that may contain non-sensitive debugging information like stack traces. IBM X- | 0.5% | — |
| CVE-2020-24349 | MED 5.5 | f5 njs njs through 0.4.3, used in NGINX, allows control-flow hijack in njs_value_property in njs_value.c. NOTE: the vendor considers the issue to be "fluff" in the NGINX use case because there is no remote attack surface. | 0.5% | — |
| CVE-2017-0301 | HIGH 7.6 | f5 big-ip_access_policy_manager In F5 BIG-IP APM software versions 11.5.0, 11.5.1, 11.5.2, 11.5.3, 11.5.4, 11.6.0, 11.6.1, 12.0.0, 12.1.0, 12.1.1 and 12.1.2 BIG-IP APM portal access requests do not return the intended resources in some cases. This may allow access to internal BIG-IP APM reso | 0.5% | — |
| CVE-2013-2232 | MED 4.9 | linux linux_kernel The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface. | 0.5% | — |
| CVE-2026-63508 | CRIT 10.0 | microsoft planetary_computer Missing authentication for critical function in Microsoft Planetary Computer Pro allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-40412 | CRIT 10.0 | microsoft azure_orbital_spatio Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-20952 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-49553 | CRIT 9.3 | adobe connect Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by an attacker to execute malicious scripts in a victim's browser. Exploitation of this issue requires user interaction in that | 0.5% | — |
| CVE-2024-50251 | MED 6.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: sanitize offset and length before calling skb_checksum() If access to offset + length is larger than the skbuff length, then skb_checksum() triggers BUG_ON(). skb_ch | 0.5% | — |
| CVE-2023-21760 | HIGH 7.1 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-42478 | HIGH 8.1 | fortinet fortisiem An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoints to brute force attack these endpoints. | 0.5% | — |
| CVE-2022-41114 | HIGH 7.0 | microsoft windows_10 Windows Bind Filter Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-33597 | LOW 3.5 | f-secure business_suite A Denial-of-Service (DoS) vulnerability was discovered in F-Secure Atlant whereby the SAVAPI component used in certain F-Secure products can crash while scanning fuzzed files. The exploit can be triggered remotely by an attacker. A successful attack will resul | 0.5% | — |
| CVE-2021-28129 | HIGH 7.8 | apache openoffice While working on Apache OpenOffice 4.1.8 a developer discovered that the DEB package did not install using root, but instead used a userid and groupid of 500. This both caused issues with desktop integration and could allow a crafted attack on files owned by t | 0.5% | — |
| CVE-2020-11608 | MED 4.3 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d. | 0.5% | — |
| CVE-2019-19047 | MED 5.5 | canonical ubuntu_linux A memory leak in the mlx5_fw_fatal_reporter_dump() function in drivers/net/ethernet/mellanox/mlx5/core/health.c in the Linux kernel before 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mlx5_crdump_collect() failures, a | 0.5% | — |