IT
58.414 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.414 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2012-4075 HIGH 7.2 cisco nx-os Cisco NX-OS allows local users to gain privileges and execute arbitrary commands via shell metacharacters in unspecified command parameters, aka Bug IDs CSCtf19827 and CSCtf27788. 0.5% —
CVE-2011-2695 MED 4.9 linux linux_kernel Multiple off-by-one errors in the ext4 subsystem in the Linux kernel before 3.0-rc5 allow local users to cause a denial of service (BUG_ON and system crash) by accessing a sparse file in extent format with a write operation involving a block number correspondi 0.5% —
CVE-2009-0342 HIGH 7.2 provos systrace Niels Provos Systrace before 1.6f on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 64-bit syscall with a syscall number that corresponds to a policy-compliant 32-bit syscall. 0.5% —
CVE-2007-5618 HIGH 7.2 vmware player Unquoted Windows search path vulnerability in the Authorization and other services in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, VMware Server before 1.0.4, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1 might allow local users to gain privi 0.5% —
CVE-2026-6928 CRIT 9.8 ibm concert IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause application crashes, or execute arbitrary code. 0.4% —
CVE-2026-53175 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush On netns teardown, fqdir_pre_exit() walks the fqdir rhashtable and flushes every fragment queue that is not yet complete 0.4% —
CVE-2026-34500 MED 6.5 apache tomcat CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. 0.4% —
CVE-2026-20343 HIGH 7.5 A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker 0.4% —
CVE-2026-20324 CRIT 9.9 A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered 0.4% —
CVE-2025-59203 MED 5.5 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows StateRepository API allows an authorized attacker to disclose information locally. 0.4% —
CVE-2025-59197 MED 5.5 microsoft windows_10_1507 Insertion of sensitive information into log file in Windows ETL Channel allows an authorized attacker to disclose information locally. 0.4% —
CVE-2025-55753 HIGH 7.5 apache http_server An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds. T 0.4% —
CVE-2025-53147 HIGH 7.0 microsoft windows_10_1507 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-38075 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix timeout on deleted connection NOPIN response timer may expire on a deleted connection and crash with such logs: Did not receive response to NOPIN on CID: 0, failing 0.4% —
CVE-2025-27759 MED 6.7 fortinet fortiweb An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiWeb version 7.6.0 through 7.6.3, 7.4.0 through 7.4.7, 7.2.0 through 7.2.10 and before 7.0.10 allows an authenticated privilege 0.4% —
CVE-2025-20218 MED 4.9 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to retrieve sensitive information from an affected device. This vulnerability is due to insufficien 0.4% —
CVE-2024-20384 MED 5.8 cisco adaptive_security_appliance_software A vulnerability in the Network Service Group (NSG) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access control list (ACL) an 0.4% —
CVE-2024-20263 MED 5.8 cisco cbs250-16p-2g_firmware A vulnerability with the access control list (ACL) management within a stacked switch configuration of Cisco Business 250 Series Smart Switches and Business 350 Series Managed Switches could allow an unauthenticated, remote attacker to bypass protection offere 0.4% —
CVE-2023-20069 MED 5.4 cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the i 0.4% —
CVE-2022-27963 MED 6.5 netsarang xftp Xftp 7.0.0088p and below contains a binary hijack vulnerability which allows attackers to execute arbitrary code via a crafted .exe file. 0.4% —
CVE-2021-36181 LOW 3.1 fortinet fortiportal A concurrent execution using shared resource with improper Synchronization vulnerability ('Race Condition') in the customer database interface of FortiPortal before 6.0.6 may allow an authenticated, low-privilege user to bring the underlying database data into 0.4% —
CVE-2020-1982 MED 4.8 paloaltonetworks pan-os Certain communication between PAN-OS and cloud-delivered services inadvertently use TLS 1.0, which is known to be a cryptographically weak protocol. These cloud services include Cortex Data Lake, the Customer Support Portal, and the Prisma Access infrastructur 0.4% —
CVE-2020-15393 MED 5.5 canonical ubuntu_linux In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770. 0.4% —
CVE-2019-4447 HIGH 7.8 ibm db2_high_performance_unload_load IBM DB2 High Performance Unload load for LUW 6.1, 6.1.0.1, 6.1.0.1 IF1, 6.1.0.2, 6.1.0.2 IF1, and 6.1.0.1 IF2 db2hpum_debug is a setuid root binary which trusts the PATH environment variable. A low privileged user can execute arbitrary commands as root by alte 0.4% —
CVE-2019-1780 MED 6.7 cisco firepower_extensible_operating_system A vulnerability in the CLI of Cisco FXOS Software and Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying operating system of an affected device with elevated privileg 0.4% —