IT
57.075 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.075 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-13019 CRIT 9.8 esri portal_for_arcgis Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes have a missing authentication for critical function vulnerability allows a remote, unauthenticated attacker to access an unprotected API. 0.4%
CVE-2025-62554 HIGH 8.4 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. 0.4%
CVE-2024-49084 HIGH 7.0 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.4%
CVE-2024-39562 HIGH 7.5 juniper junos_os_evolved A Missing Release of Resource after Effective Lifetime vulnerability the xinetd process, responsible for spawning SSH daemon (sshd) instances, of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause a Denial of Service (D 0.4%
CVE-2023-45587 LOW 3.5 fortinet fortisandbox An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 al 0.4%
CVE-2023-41844 LOW 3.5 fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all 0.4%
CVE-2023-41681 HIGH 7.5 fortinet fortisandbox A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, FortiSandbox 4.2.1 through 4.2.5, FortiSandbox 4.0.0 through 4.0.3, FortiSandbox 3.2 all versions, FortiSandbox 3 0.4%
CVE-2023-33303 HIGH 8.1 fortinet fortiedr A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request 0.4%
CVE-2023-21561 HIGH 7.8 microsoft windows_10_1607 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0.4%
CVE-2023-21551 HIGH 7.8 microsoft windows_10_1809 Microsoft Cryptographic Services Elevation of Privilege Vulnerability 0.4%
CVE-2022-47983 MED 5.4 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trust 0.4%
CVE-2022-35704 HIGH 7.8 adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a v 0.4%
CVE-2022-1016 MED 5.5 linux linux_kernel A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivi 0.4%
CVE-2021-1308 HIGH 7.4 cisco rv132w_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload 0.4%
CVE-2021-1251 HIGH 7.4 cisco rv132w_firmware Multiple vulnerabilities exist in the Link Layer Discovery Protocol (LLDP) implementation for Cisco Small Business RV Series Routers. An unauthenticated, adjacent attacker could execute arbitrary code or cause an affected router to leak system memory or reload 0.4%
CVE-2020-35451 MED 4.7 apache oozie There is a race condition in OozieSharelibCLI in Apache Oozie before version 5.2.1 which allows a malicious attacker to replace the files in Oozie's sharelib during it's creation. 0.4%
CVE-2019-20422 MED 5.5 linux linux_kernel In the Linux kernel before 5.3.4, fib6_rule_lookup in net/ipv6/ip6_fib.c mishandles the RT6_LOOKUP_F_DST_NOREF flag in a reference-count decision, leading to (for example) a crash that was identified by syzkaller, aka CID-7b09c2d052db. 0.4%
CVE-2017-15870 MED 6.7 paloaltonetworks globalprotect Palo Alto Networks GlobalProtect Agent before 4.0.3 allows attackers with administration rights on the local station to gain SYSTEM privileges via vectors involving "image path execution hijacking." 0.4%
CVE-2017-15868 HIGH 7.8 canonical ubuntu_linux The bnep_add_connection function in net/bluetooth/bnep/core.c in the Linux kernel before 3.19 does not ensure that an l2cap socket is available, which allows local users to gain privileges via a crafted application. 0.4%
CVE-2017-12239 MED 6.8 cisco ios_xe A vulnerability in motherboard console ports of line cards for Cisco ASR 1000 Series Aggregation Services Routers and Cisco cBR-8 Converged Broadband Routers could allow an unauthenticated, physical attacker to access an affected device's operating system. The 0.4%
CVE-2016-10147 MED 5.5 linux linux_kernel crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5). 0.4%
CVE-2015-4167 MED 4.7 canonical ubuntu_linux The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF files 0.4%
CVE-2013-7268 MED 4.9 linux linux_kernel The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory v 0.4%
CVE-2013-7267 MED 4.9 linux linux_kernel The atalk_recvmsg function in net/appletalk/ddp.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel mem 0.4%
CVE-2013-7266 MED 4.9 linux linux_kernel The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kernel before 3.12.4 does not ensure that a certain length value is consistent with the size of an associated data structure, which allows local users to obtain sensitive information f 0.4%