IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-52480 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix race condition between session lookup and expire Thread A + Thread B ksmbd_session_lookup | smb2_sess_setup sess = xa_load 0.5% —
CVE-2023-28272 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.5% —
CVE-2023-20245 MED 5.8 cisco adaptive_security_appliance_software Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and 0.5% —
CVE-2023-20184 MED 5.4 cisco catalyst_center Multiple vulnerabilities in the API of Cisco DNA Center Software could allow an authenticated, remote attacker to read information from a restricted container, enumerate user information, or execute arbitrary commands in a restricted container as the root user 0.5% —
CVE-2022-3643 MED 6.5 debian debian_linux Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears to be an (unwritten?) assumption in the rest 0.5% —
CVE-2022-27966 MED 6.5 netsarang xshell Xshell v7.0.0099 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. 0.5% —
CVE-2022-27965 MED 6.5 netsarang xlpd Xlpd v7.0.0094 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. 0.5% —
CVE-2022-27964 MED 6.5 netsarang xmanager Xmanager v7.0.0096 and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. 0.5% —
CVE-2022-27503 MED 6.1 citrix storefront_server Cross-site Scripting (XSS) vulnerability in Citrix StoreFront affects version 1912 before CU5 and version 3.12 before CU9 0.5% —
CVE-2022-20663 MED 6.1 cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Stealthwatch Enterprise, could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The 0.5% —
CVE-2021-42286 HIGH 7.8 microsoft windows_10 Windows Core Shell SI Host Extension Framework for Composable Shell Elevation of Privilege Vulnerability 0.5% —
CVE-2021-42283 HIGH 8.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5% —
CVE-2021-41377 HIGH 7.8 microsoft windows_10 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability 0.5% —
CVE-2021-41370 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5% —
CVE-2021-41367 HIGH 7.8 microsoft windows_10 NTFS Elevation of Privilege Vulnerability 0.5% —
CVE-2021-41366 HIGH 7.8 microsoft windows_10 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability 0.5% —
CVE-2021-36957 HIGH 7.8 microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability 0.5% —
CVE-2021-3564 MED 5.5 debian debian_linux A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versi 0.5% —
CVE-2020-5869 CRIT 9.1 f5 big-iq_centralized_management In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. 0.5% —
CVE-2015-8569 LOW 2.3 linux linux_kernel The (1) pptp_bind and (2) pptp_connect functions in drivers/net/ppp/pptp.c in the Linux kernel through 4.3.3 do not verify an address length, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism 0.5% —
CVE-2011-1182 LOW 3.6 linux linux_kernel kernel/signal.c in the Linux kernel before 2.6.39 allows local users to spoof the uid and pid of a signal sender via a sigqueueinfo system call. 0.5% —
CVE-2011-1023 MED 4.9 linux linux_kernel The Reliable Datagram Sockets (RDS) subsystem in the Linux kernel before 2.6.38 does not properly handle congestion map updates, which allows local users to cause a denial of service (BUG_ON and system crash) via vectors involving (1) a loopback (aka loop) tra 0.5% —
CVE-2009-1630 MED 4.4 canonical ubuntu_linux The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions 0.5% —
CVE-2003-1161 HIGH 7.2 linux linux_kernel exit.c in Linux kernel 2.6-test9-CVS, as stored on kernel.bkbits.net, was modified to contain a backdoor, which could allow local users to elevate their privileges by passing __WCLONE|__WALL to the sys_wait4 function. 0.5% —
CVE-2026-67588 HIGH 7.5 apache qpid_protonj2 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the 0.5% —