58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.290 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-8659 | MED 6.0 | rapid7 insightconnect_sqlmap OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation. | 1.3% | — |
| CVE-2026-8658 | MED 6.0 | rapid7 insightconnect_tcpdump OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction. | 1.3% | — |
| CVE-2026-21248 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.3% | — |
| CVE-2026-21244 | HIGH 7.3 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally. | 1.3% | — |
| CVE-2025-29804 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 1.3% | — |
| CVE-2024-49127 | HIGH 8.1 | microsoft windows_10_1507 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-49126 | HIGH 8.1 | microsoft windows_10_1507 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability | 1.3% | — |
| CVE-2024-23538 | CRIT 9.9 | apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Fineract.This issue affects Apache Fineract: <1.8.5. Users are recommended to upgrade to version 1.8.5 or 1.9.0, which fix the issue. | 1.3% | — |
| CVE-2022-29376 | HIGH 8.8 | apachefriends xampp Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory. | 1.3% | — |
| CVE-2020-7882 | HIGH 7.5 | hancom anysign4pc Using the parameter of getPFXFolderList function, attackers can see the information of authorization certification and delete the files. It occurs because the parameter contains path traversal characters(ie. '../../../') | 1.3% | — |
| CVE-2015-5363 | MED 5.0 | juniper junos The SRX Network Security Daemon (nsd) in Juniper SRX Series services gateways with Junos 12.1X44 before 12.1X44-D50, 12.1X46 before 12.1X46-D35, 12.1X47 before 12.1X47-D25, and 12.3X48 before 12.3X48-D15 allows remote DNS servers to cause a denial of service ( | 1.3% | — |
| CVE-2014-1211 | MED 6.8 | vmware vcloud_director Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout. | 1.3% | — |
| CVE-2010-3048 | HIGH 7.5 | cisco unified_personal_communicator Cisco Unified Personal Communicator 7.0 (1.13056) does not free allocated memory for received data and does not perform validation if memory allocation is successful, causing a remote denial of service condition. | 1.3% | — |
| CVE-2007-3724 | LOW 2.1 | microsoft windows_xp The process scheduler in the Microsoft Windows XP kernel does not make use of the process statistics kept by the kernel, performs scheduling based on CPU billing gathered from periodic process sampling ticks, and gives preference to "interactive" processes tha | 1.3% | — |
| CVE-2003-0305 | MED 5.0 | cisco ios The Service Assurance Agent (SAA) in Cisco IOS 12.0 through 12.2, aka Response Time Reporter (RTR), allows remote attackers to cause a denial of service (crash) via malformed RTR packets to port 1967. | 1.3% | — |
| CVE-2001-0754 | MED 5.0 | cisco cbos Cisco CBOS 2.3.8 and earlier allows remote attackers to cause a denial of service via a series of large ICMP ECHO REPLY (ping) packets, which cause it to enter ROMMON mode and stop forwarding packets. | 1.3% | — |
| CVE-2001-0057 | MED 5.0 | cisco broadband_operating_system Cisco 600 routers running CBOS 2.4.1 and earlier allow remote attackers to cause a denial of service via a large ICMP echo (ping) packet. | 1.3% | — |
| CVE-2001-0055 | MED 5.0 | cisco broadband_operating_system CBOS 2.4.1 and earlier in Cisco 600 routers allows remote attackers to cause a denial of service via a slow stream of TCP SYN packets. | 1.3% | — |
| CVE-2024-38081 | HIGH 7.3 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1.3% | — |
| CVE-2023-49733 | CRIT 9.8 | apache cocoon Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. Users are recommended to upgrade to version 2.3.0, which fixes the issue. | 1.3% | — |
| CVE-2023-40581 | HIGH 8.3 | yt-dlp_project yt-dlp yt-dlp is a youtube-dl fork with additional features and fixes. yt-dlp allows the user to provide shell command lines to be executed at various stages in its download steps through the `--exec` flag. This flag allows output template expansion in its argument, | 1.3% | — |
| CVE-2022-40160 | MED 6.5 | apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then | 1.3% | — |
| CVE-2022-40159 | MED 6.5 | apache commons_jxpath ** DISPUTED ** This record was originally reported by the oss-fuzz project who failed to consider the security context in which JXPath is intended to be used and failed to contact the JXPath maintainers prior to requesting the CVE allocation. The CVE was then | 1.3% | — |
| CVE-2022-20748 | MED 5.3 | cisco secure_firewall_threat_defense A vulnerability in the local malware analysis process of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to insufficien | 1.3% | — |
| CVE-2022-20675 | MED 5.3 | cisco asyncos A vulnerability in the TCP/IP stack of Cisco Email Security Appliance (ESA), Cisco Web Security Appliance (WSA), and Cisco Secure Email and Web Manager, formerly Security Management Appliance, could allow an unauthenticated, remote attacker to crash the Simple | 1.3% | — |