IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-39015 MED 5.4 ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to cr 0.5% —
CVE-2021-23026 HIGH 8.8 f5 big-ip_access_policy_manager BIG-IP version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x and 11.6.x and all versions of BIG-IQ 8.x, 7.x, and 6.x are vulnerable to cross-site request forgery (CSRF) attacks through 0.5% —
CVE-2021-1476 MED 6.7 cisco adaptive_security_appliance_software A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected d 0.5% —
CVE-2019-5535 MED 4.7 vmware fusion VMware Workstation and Fusion contain a network denial-of-service vulnerability due to improper handling of certain IPv6 packets. VMware has evaluated the severity of this issue to be in the Moderate severity range with a maximum CVSSv3 base score of 4.7. 0.5% —
CVE-2019-19954 HIGH 7.3 signal signal-desktop Signal Desktop before 1.29.1 on Windows allows local users to gain privileges by creating a Trojan horse %SYSTEMDRIVE%\node_modules\.bin\wmic.exe file. 0.5% —
CVE-2019-11190 MED 4.7 linux linux_kernel The Linux kernel before 4.8 allows local users to bypass ASLR on setuid programs (such as /bin/su) because install_exec_creds() is called too late in load_elf_binary() in fs/binfmt_elf.c, and thus the ptrace_may_access() check has a race condition when reading 0.5% —
CVE-2018-15402 MED 5.4 cisco enterprise_network_virtualization_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to conduct cross-site request forgery (CSRF) attacks. The vulnerability is due to improper validation of Origin headers on HTTP requests wit 0.5% —
CVE-2016-2549 MED 6.2 linux linux_kernel sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call. 0.5% —
CVE-2011-4098 LOW 1.9 linux linux_kernel The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory. 0.5% —
CVE-2011-3209 MED 4.9 linux linux_kernel The div_long_long_rem implementation in include/asm-x86/div64.h in the Linux kernel before 2.6.26 on the x86 platform allows local users to cause a denial of service (Divide Error Fault and panic) via a clock_gettime system call. 0.5% —
CVE-2011-2525 HIGH 7.8 linux linux_kernel The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer derefe 0.5% —
CVE-2026-82434 MED 6.5 Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payload` in the topology configuration, because workers need it. Nimbus then served that configuration verbatim to any caller holding read-only 0.5% —
CVE-2026-62742 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5% —
CVE-2026-62718 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5% —
CVE-2026-62715 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5% —
CVE-2026-5860 HIGH 8.8 google chrome Use after free in WebRTC in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.5% —
CVE-2026-42930 HIGH 8.7 f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Appliance mode restrictions on a BIG-IP system.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.5% —
CVE-2026-33582 MED 6.5 apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the 0.5% —
CVE-2026-22732 CRIT 9.1 vmware spring_security When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written.  This issue affects Spring Security Servlet applications using lazy (default) writing of HTTP He 0.5% —
CVE-2025-25004 HIGH 7.3 microsoft powershell Improper access control in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. 0.5% —
CVE-2025-12382 HIGH 8.8 algosec firewall_analyzer Improper Limitation of a Pathname 'Path Traversal') vulnerability in Algosec Firewall Analyzer on Linux, 64 bit allows an authenticated user to upload files to a restricted directory leading to code injection. This issue affects Algosec Firewall Analyzer: A33. 0.5% —
CVE-2024-38157 HIGH 7.0 microsoft azure_iot_hub_device_client_sdk Azure IoT SDK Remote Code Execution Vulnerability 0.5% —
CVE-2024-20299 MED 5.8 cisco adaptive_security_appliance_software A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic 0.5% —
CVE-2024-20297 MED 5.8 cisco adaptive_security_appliance_software A vulnerability in the AnyConnect firewall for Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) and allow traffic 0.5% —
CVE-2022-35762 HIGH 7.8 microsoft windows_10 Storage Spaces Direct Elevation of Privilege Vulnerability 0.5% —