57.380 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.380 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-34884 | CRIT 9.8 | apache skywalking_mcp SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking MCP: 0.1.0. Users are recommended to upgrade to version 0.2.0, which fixes this issue. | 0.5% | — |
| CVE-2025-38430 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: nfsd: nfsd4_spo_must_allow() must check this is a v4 compound request If the request being processed is not a v4 compound request, then examining the cstate can have undefined results. This | 0.5% | — |
| CVE-2025-29808 | MED 5.5 | microsoft windows_server_2022 Use of a cryptographic primitive with a risky implementation in Windows Cryptographic Services allows an authorized attacker to disclose information locally. | 0.5% | — |
| CVE-2025-26467 | HIGH 8.8 | apache cassandra Privilege Defined With Unsafe Actions vulnerability in Apache Cassandra. An user with MODIFY permission ON ALL KEYSPACES can escalate privileges to superuser within a targeted Cassandra cluster via unsafe actions to a system resource. Operators granting data M | 0.5% | — |
| CVE-2025-21382 | HIGH 7.8 | microsoft windows_10_1809 Windows Graphics Component Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-53073 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Never decrement pending_async_copies on error The error flow in nfsd4_copy() calls cleanup_async_copy(), which already decrements nn->pending_async_copies. | 0.5% | — |
| CVE-2024-39555 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker sending a specific malformed BGP update message to cause the session to reset, resulting in a | 0.5% | — |
| CVE-2024-36964 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This was presuma | 0.5% | — |
| CVE-2024-0008 | MED 6.6 | paloaltonetworks pan-os Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access. | 0.5% | — |
| CVE-2022-22405 | MED 5.9 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle | 0.5% | — |
| CVE-2021-47374 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-debug: prevent an error message from causing runtime problems For some drivers, that use the DMA API. This error message can be reached several millions of times per second, causing spam | 0.5% | — |
| CVE-2020-29014 | MED 6.3 | fortinet fortisandbox A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of FortiSandbox before 3.2.2 may allow an authenticated attacker to bring the system into an unresponsive state via specifically orchestrated seq | 0.5% | — |
| CVE-2019-5522 | HIGH 7.1 | vmware tools VMware Tools for Windows update addresses an out of bounds read vulnerability in vm3dmp driver which is installed with vmtools in Windows guest machines. This issue is present in versions 10.2.x and 10.3.x prior to 10.3.10. A local attacker with non-administra | 0.5% | — |
| CVE-2019-25045 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 5.0.19. The XFRM subsystem has a use-after-free, related to an xfrm_state_fini panic, aka CID-dbb2483b2a46. | 0.5% | — |
| CVE-2019-19083 | MED 4.7 | canonical ubuntu_linux Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc in the Linux kernel before 5.3.8 allow attackers to cause a denial of service (memory consumption). This affects the dce112_clock_source_create() function in drivers/gpu/drm/ | 0.5% | — |
| CVE-2019-1791 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands with elevated privileges on the underlying operating system of an affected device. The vulnerability is | 0.5% | — |
| CVE-2019-1591 | HIGH 7.8 | cisco nx-os A vulnerability in a specific CLI command implementation of Cisco Nexus 9000 Series ACI Mode Switch Software could allow an authenticated, local attacker to escape a restricted shell on an affected device. The vulnerability is due to insufficient sanitization | 0.5% | — |
| CVE-2017-6606 | MED 6.4 | cisco ios_xe A vulnerability in a startup script of Cisco IOS XE Software could allow an unauthenticated attacker with physical access to the targeted system to execute arbitrary commands on the underlying operating system with the privileges of the root user. More Informa | 0.5% | — |
| CVE-2026-63795 | CRIT 10.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been | 0.5% | — |
| CVE-2026-5865 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-57990 | HIGH 7.4 | microsoft edge_chromium Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-4673 | HIGH 8.8 | google chrome Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-44631 | CRIT 9.8 | apache http_server Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | 0.5% | — |
| CVE-2026-20190 | HIGH 7.5 | cisco identity_services_engine A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit t | 0.5% | — |
| CVE-2025-53736 | MED 6.8 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information locally. | 0.5% | — |