57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-39811 | MED 4.9 | fortinet fortiweb A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack ve | 0.4% | — |
| CVE-2026-32216 | MED 5.5 | microsoft windows_11_26h1 Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally. | 0.4% | — |
| CVE-2026-31611 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: require 3 sub-authorities before reading sub_auth[2] parse_dacl() compares each ACE SID against sid_unix_NFS_mode and on match reads sid.sub_auth[2] as the file mode. If sid_unix_NFS | 0.4% | — |
| CVE-2026-20916 | HIGH 8.1 | f5 big-iq_centralized_management An authenticated iControl REST user with low privileges can create or modify arbitrary files through an undisclosed iControl REST endpoint on the BIG-IQ system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.4% | — |
| CVE-2026-20809 | HIGH 7.8 | microsoft windows_10_1607 Time-of-check time-of-use (toctou) race condition in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20065 | MED 5.8 | cisco secure_firewall_threat_defense Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. This vulnerabil | 0.4% | — |
| CVE-2025-62474 | HIGH 7.8 | microsoft windows_10_1607 Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-47967 | MED 4.7 | microsoft edge Insufficient ui warning of dangerous operations in Microsoft Edge for Android allows an unauthorized attacker to perform spoofing over a network. | 0.4% | — |
| CVE-2025-29838 | HIGH 7.4 | microsoft windows_11_24h2 Null pointer dereference in Windows Drivers allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2024-5908 | HIGH 7.5 | paloaltonetworks globalprotect A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when gen | 0.4% | — |
| CVE-2024-49060 | HIGH 8.8 | microsoft azure_stack_hci Azure Stack HCI Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-39554 | MED 5.9 | juniper junos A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attack | 0.4% | — |
| CVE-2024-30275 | HIGH 7.8 | adobe aero Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mali | 0.4% | — |
| CVE-2024-20363 | MED 5.8 | cisco secure_firewall_threat_defense Multiple Cisco products are affected by a vulnerability in the Snort Intrusion Prevention System (IPS) rule engine that could allow an unauthenticated, remote attacker to bypass the configured rules on an affected system. This vulnerability is due to incorrect | 0.4% | — |
| CVE-2023-28972 | MED 6.8 | juniper junos An Improper Link Resolution Before File Access vulnerability in console port access of Juniper Networks Junos OS on NFX Series allows an attacker to bypass console access controls. When "set system ports console insecure" is enabled, root login is disallowed f | 0.4% | — |
| CVE-2023-1187 | LOW 3.3 | fabulatech webcam_for_remote_desktop A vulnerability was found in FabulaTech Webcam for Remote Desktop 2.8.42 and classified as problematic. This issue affects some unknown processing in the library ftwebcam.sys of the component Global Variable Handler. The manipulation leads to denial of service | 0.4% | — |
| CVE-2022-35646 | MED 5.9 | ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.0.1 software component could allow an authenticated user to modify or cancel any other user's access request using man-in-the-middle techniques. IBM X-Force ID: 231096. | 0.4% | — |
| CVE-2021-3506 | HIGH 7.1 | debian debian_linux An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a lea | 0.4% | — |
| CVE-2021-34726 | MED 6.7 | cisco sd-wan A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device. This vulnerability is due to insuf | 0.4% | — |
| CVE-2021-29647 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624. | 0.4% | — |
| CVE-2020-25639 | MED 4.4 | fedoraproject fedora A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local user to crash the system. | 0.4% | — |
| CVE-2020-10773 | MED 4.4 | linux linux_kernel A stack information leak flaw was found in s390/s390x in the Linux kernel’s memory manager functionality, where it incorrectly writes to the /proc/sys/vm/cmm_timeout file. This flaw allows a local user to see the kernel data. | 0.4% | — |
| CVE-2019-16151 | MED 4.7 | fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execu | 0.4% | — |
| CVE-2019-11486 | HIGH 7.0 | debian debian_linux The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions. | 0.4% | — |
| CVE-2017-9076 | HIGH 7.8 | debian debian_linux The dccp_v6_request_recv_sock function in net/dccp/ipv6.c in the Linux kernel through 4.11.1 mishandles inheritance, which allows local users to cause a denial of service or possibly have unspecified other impact via crafted system calls, a related issue to CV | 0.4% | — |