57.288 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.288 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-28923 | MED 6.4 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2024-2551 | HIGH 7.5 | paloaltonetworks pan-os A null pointer dereference vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to stop a core system service on the firewall by sending a crafted packet through the data plane that causes a denial of service (DoS) condition. | 0.5% | — |
| CVE-2023-20223 | HIGH 8.6 | cisco dna_center A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control enforcement on AP | 0.5% | — |
| CVE-2023-20188 | MED 4.8 | cisco sf200-24_firmware A vulnerability in the web-based management interface of Cisco Small Business 200 Series Smart Switches, Cisco Small Business 300 Series Managed Switches, and Cisco Small Business 500 Series Stackable Managed Switches could allow an authenticated, remote attac | 0.5% | — |
| CVE-2021-47496 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: Fix flipped sign in tls_err_abort() calls sk->sk_err appears to expect a positive value, a convention that ktls doesn't always follow and that leads to memory corruption in other co | 0.5% | — |
| CVE-2021-20455 | LOW 3.7 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against th | 0.5% | — |
| CVE-2020-11668 | HIGH 7.1 | linux linux_kernel In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770. | 0.5% | — |
| CVE-2019-6687 | HIGH 7.4 | f5 big-ip_application_security_manager On versions 15.0.0-15.0.1.1, the BIG-IP ASM Cloud Security Services profile uses a built-in verification mechanism that fails to properly authenticate the X.509 certificate of remote endpoints. | 0.5% | — |
| CVE-2017-12301 | MED 6.7 | cisco nx-os A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and gain unauthorized access to the underlying operating system of the device. The vulnerability exists due to in | 0.5% | — |
| CVE-2016-4565 | HIGH 7.8 | canonical ubuntu_linux The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. | 0.5% | — |
| CVE-2015-4224 | HIGH 7.2 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474. | 0.5% | — |
| CVE-2015-4106 | MED 4.6 | canonical ubuntu_linux QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other u | 0.5% | — |
| CVE-2011-2495 | LOW 2.1 | linux linux_kernel fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user's password. | 0.5% | — |
| CVE-2010-2962 | HIGH 7.2 | canonical ubuntu_linux drivers/gpu/drm/i915/i915_gem.c in the Graphics Execution Manager (GEM) in the Intel i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 2.6.36 does not properly validate pointers to blocks of memory, which allows local users | 0.5% | — |
| CVE-2026-67588 | HIGH 7.5 | apache qpid_protonj2 A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid ProtonJ2: through 1.1.0. Users are recommended to upgrade to version 1.2.0, which fixes the | 0.5% | — |
| CVE-2026-62915 | MED 6.5 | microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2026-61920 | MED 6.6 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network. | 0.5% | — |
| CVE-2026-58076 | HIGH 8.8 | apache airflow Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's | 0.5% | — |
| CVE-2026-57106 | CRIT 10.0 | microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. | 0.5% | — |
| CVE-2025-47857 | MED 6.7 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in Fortinet FortiWeb CLI version 7.6.0 through 7.6.3 and before 7.4.8 allows a privileged attacker to execute arbitrary code or command via craf | 0.5% | — |
| CVE-2024-53959 | HIGH 7.8 | adobe framemaker Adobe Framemaker versions 2020.7, 2022.5 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vi | 0.5% | — |
| CVE-2024-33505 | MED 5.6 | fortinet fortianalyzer A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allow | 0.5% | — |
| CVE-2024-20675 | MED 6.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2023-32053 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-25840 | LOW 3.4 | esri arcgis_server There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authenticated attacker to create a crafted link which onmouseover wont execute but could potentially render an image in the victims browser. The | 0.5% | — |