IT
57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-12313 MED 6.7 cisco packet_tracer An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the in 0.5%
CVE-2017-12312 MED 6.7 cisco advanced_malware_protection_for_endpoints An untrusted search path (aka DLL Preloading) vulnerability in the Cisco Immunet antimalware installer could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the installe 0.5%
CVE-2026-64450 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: fix out-of-bounds read in broadcast Gap ACK blocks A broadcast PROTOCOL/STATE_MSG can carry a Gap ACK blocks record in its data area. tipc_get_gap_ack_blks() only verifies that the rec 0.5%
CVE-2026-62814 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network. 0.5%
CVE-2026-52958 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in osdmap_decode() When decoding osd_state and osd_weight from an incoming osdmap in osdmap_decode(), both are decoded for each osd, i.e., map->ma 0.5%
CVE-2026-43407 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type CEPH_M 0.5%
CVE-2025-62233 MED 6.3 apache dolphinscheduler Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler:  Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a Sta 0.5%
CVE-2023-35020 MED 5.4 ibm sterling_control_center IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874. 0.5%
CVE-2022-36077 HIGH 7.2 electronjs electron The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, 0.5%
CVE-2021-3039 LOW 3.8 paloaltonetworks prisma_cloud An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role 0.5%
CVE-2017-4028 MED 5.0 mcafee anti-virus_plus Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. 0.5%
CVE-2016-9795 HIGH 7.8 broadcom ca_workload_automation_ae The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infr 0.5%
CVE-2015-8966 HIGH 7.8 linux linux_kernel arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD_GETLK, (2) F_OFD_SETLK, or (3) F_OFD_SETLKW command in an fcntl64 system call. 0.5%
CVE-2015-7600 HIGH 7.2 cisco vpn_client Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section. 0.5%
CVE-2015-6303 MED 4.3 cisco spark The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs 0.5%
CVE-2026-9119 HIGH 8.8 google chrome Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) 0.5%
CVE-2026-69282 HIGH 8.8 microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-69273 HIGH 8.8 microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.5%
CVE-2026-62872 HIGH 8.8 microsoft .net_framework Incorrect authorization in .NET Framework allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2026-42535 CRIT 9.1 apache http_server A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing child process crashes. Users are recommended to upgrade to version 2.4.68, which fixes t 0.5%
CVE-2025-55332 MED 6.1 microsoft windows_10_1809 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2025-55330 MED 6.1 microsoft windows_11_22h2 Improper enforcement of behavioral workflow in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.5%
CVE-2024-43584 HIGH 7.7 microsoft windows_11_21h2 Windows Scripting Engine Security Feature Bypass Vulnerability 0.5%
CVE-2024-21595 HIGH 7.5 juniper junos An Improper Validation of Syntactic Correctness of Input vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). If an attacker sends high rate of s 0.5%
CVE-2024-0095 CRIT 9.0 nvidia triton_inference_server NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where a user can inject forged logs and executable commands by injecting arbitrary data as a new log entry. A successful exploit of this vulnerability might lead to code execution, d 0.5%