58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26008 | MED 5.3 | fortinet fortios An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through | 0.5% | — |
| CVE-2024-22280 | HIGH 8.5 | vmware aria_automation VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database. | 0.5% | — |
| CVE-2023-26206 | MED 6.8 | fortinet fortinac An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.1.10 and 7.2.0 allows an attacker to execute unauthorized code or commands via the name fields observed in the | 0.5% | — |
| CVE-2022-38412 | HIGH 7.8 | adobe animate Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vu | 0.5% | — |
| CVE-2022-30307 | LOW 3.9 | fortinet fortios A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow an unauthenticated attacker to perform a man in the middle attack. | 0.5% | — |
| CVE-2022-27484 | MED 5.4 | fortinet fortiadc A unverified password change in Fortinet FortiADC version 6.2.0 through 6.2.3, 6.1.x, 6.0.x, 5.x.x allows an authenticated attacker to bypass the Old Password check in the password change form via a crafted HTTP request. | 0.5% | — |
| CVE-2021-46873 | MED 5.3 | wireguard wireguard WireGuard, such as WireGuard 0.5.3 on Windows, does not fully account for the possibility that an adversary might be able to set a victim's system time to a future value, e.g., because unauthenticated NTP is used. This can lead to an outcome in which one stati | 0.5% | — |
| CVE-2021-34693 | MED 5.5 | debian debian_linux net/can/bcm.c in the Linux kernel through 5.12.10 allows local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized. | 0.5% | — |
| CVE-2020-27696 | HIGH 7.8 | trendmicro antivirus\+_security_2020 Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product. | 0.5% | — |
| CVE-2020-27695 | HIGH 7.8 | trendmicro antivirus\+_security_2020 Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product. | 0.5% | — |
| CVE-2019-1606 | HIGH 7.8 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to c | 0.5% | — |
| CVE-2017-8068 | HIGH 7.8 | linux linux_kernel drivers/net/usb/pegasus.c in the Linux kernel 4.9.x before 4.9.11 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspecified other impact by le | 0.5% | — |
| CVE-2015-2041 | MED 4.6 | debian debian_linux net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entr | 0.5% | — |
| CVE-2011-4132 | LOW 2.1 | linux linux_kernel The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value." | 0.5% | — |
| CVE-2011-3619 | MED 4.6 | linux linux_kernel The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 3.0 does not properly handle invalid parameters, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified othe | 0.5% | — |
| CVE-2006-4093 | MED 4.9 | canonical ubuntu_linux Linux kernel 2.x.6 before 2.6.17.9 and 2.4.x before 2.4.33.1 on PowerPC PPC970 systems allows local users to cause a denial of service (crash) related to the "HID0 attention enable on PPC970 at boot time." | 0.5% | — |
| CVE-2006-1862 | MED 4.9 | linux linux_kernel The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load. | 0.5% | — |
| CVE-2026-62896 | CRIT 9.6 | microsoft teams Improper authentication in Microsoft Teams allows an authorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2026-62764 | MED 6.5 | apache accumulo Improper Handling of Insufficient Privileges vulnerability in Apache Accumulo. An authenticated, but low-privileged user without system permissions may issue a remote command to gracefully shutdown system components (compaction-coordinator, compactor, gc, mana | 0.5% | — |
| CVE-2026-49176 | HIGH 7.8 | microsoft windows_10_1607 Improper privilege management in Windows WalletService allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-26640 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Digital Media allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-23326 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause an integer overflow through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service. | 0.5% | — |
| CVE-2025-23325 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause uncontrolled recursion through a specially crafted input. A successful exploit of this vulnerability might lead to denial of service. | 0.5% | — |
| CVE-2025-23324 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead t | 0.5% | — |
| CVE-2025-21370 | HIGH 7.8 | microsoft windows_11_22h2 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability | 0.5% | — |