57.162 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.162 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-6654 | MED 4.3 | f5 big-ip_access_policy_manager On versions 14.0.0-14.1.2, 13.0.0-13.1.3, 12.1.0-12.1.5, and 11.5.1-11.6.5, the BIG-IP system fails to perform Martian Address Filtering (As defined in RFC 1812 section 5.3.7) on the control plane (management interface). This may allow attackers on an adjacent | 0.5% | — |
| CVE-2015-5361 | MED 6.5 | juniper junos Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specific to source and destination IPs and ports of client and serve | 0.5% | — |
| CVE-2013-7339 | MED 4.7 | linux linux_kernel The rds_ib_laddr_check function in net/rds/ib.c in the Linux kernel before 3.12.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on | 0.5% | — |
| CVE-2013-4512 | MED 4.7 | linux linux_kernel Buffer overflow in the exitcode_proc_write function in arch/um/kernel/exitcode.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging root privileges for a write operation. | 0.5% | — |
| CVE-2013-3392 | MED 4.3 | cisco webex_social Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco WebEx Social allow remote attackers to hijack the authentication of arbitrary users via unspecified vectors, aka Bug IDs CSCuh10405 and CSCuh10355. | 0.5% | — |
| CVE-2012-1717 | LOW 2.1 | oracle jdk Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors rela | 0.5% | — |
| CVE-2006-6921 | LOW 2.1 | linux linux_kernel Unspecified versions of the Linux kernel allow local users to cause a denial of service (unrecoverable zombie process) via a program with certain instructions that prevent init from properly reaping a child whose parent has died. | 0.5% | — |
| CVE-2006-1862 | MED 4.9 | linux linux_kernel The virtual memory implementation in Linux kernel 2.6.x allows local users to cause a denial of service (panic) by running lsof a large number of times in a way that produces a heavy system load. | 0.5% | — |
| CVE-2026-64397 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests u | 0.5% | — |
| CVE-2026-40963 | LOW 3.1 | apache airflow The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated UI/API user authorized for one Dag could enumerate linked Dag | 0.5% | — |
| CVE-2026-28811 | HIGH 7.5 | apache jspwiki Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this issue. | 0.5% | — |
| CVE-2026-23794 | MED 6.8 | apache syncope Reflected XSS in Apache Syncope's Enduser Login page. An attacker that tricks a legitimate user into clicking a malicious link and logging in to Syncope Enduser could steal that user's credentials. This issue affects Apache Syncope: from 3.0 through 3.0.15, f | 0.5% | — |
| CVE-2026-20957 | HIGH 7.8 | microsoft 365_apps Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.5% | — |
| CVE-2026-20859 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.5% | — |
| CVE-2025-55226 | MED 6.7 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Graphics Kernel allows an authorized attacker to execute code locally. | 0.5% | — |
| CVE-2025-38052 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done Syzbot reported a slab-use-after-free with the following call trace: ===================================================== | 0.5% | — |
| CVE-2024-50086 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix user-after-free from session log off There is racy issue between smb2 session log off and smb2 session setup. It will cause user-after-free from session log off. This add session_ | 0.5% | — |
| CVE-2024-20466 | MED 6.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability is due to improper enforcement of admini | 0.5% | — |
| CVE-2023-36698 | MED 4.4 | microsoft windows_10_1809 Windows Kernel Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2023-3268 | HIGH 7.1 | debian debian_linux An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information. | 0.5% | — |
| CVE-2022-38373 | HIGH 8.0 | fortinet fortideceptor An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.1, 4.0.2 may allow an authenticated user to perform a cross site scripting (XSS) attack via sending requests wi | 0.5% | — |
| CVE-2022-34263 | HIGH 7.8 | adobe illustrator Adobe Illustrator versions 26.3.1 (and earlier) and 25.4.6 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th | 0.5% | — |
| CVE-2022-27659 | MED 4.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, and 14.1.x versions prior to 14.1.4.6, an authenticated attacker can modify or delete Dashboards created by other BIG-IP users in the Traffic Management User Interface (TMUI). N | 0.5% | — |
| CVE-2022-24680 | HIGH 7.8 | trendmicro apex_one A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local at | 0.5% | — |
| CVE-2022-24679 | HIGH 7.8 | trendmicro apex_one A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local at | 0.5% | — |