IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-4270 LOW 3.6 linux linux_kernel The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application. 0.5%
CVE-2009-0056 MED 6.8 cisco ironport_encryption_appliance Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 0.5%
CVE-2026-9639 MED 6.5 canonical lxd Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of service via a specially crafted custom-volume backup tarball that o 0.5%
CVE-2026-66321 HIGH 7.4 microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.5%
CVE-2026-64113 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb 0.5%
CVE-2026-21247 HIGH 7.3 microsoft windows_10_1607 Improper input validation in Windows Hyper-V allows an authorized attacker to execute code locally. 0.5%
CVE-2025-14728 MED 6.8 rapid7 velociraptor Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore direct 0.5%
CVE-2024-32049 HIGH 7.4 f5 big-ip_next_central_manager BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. 0.5%
CVE-2022-39954 HIGH 7.3 fortinet fortinac An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, FortiNAC version 9.1.0 through 9.1.8, FortiNAC version 8.8.0 through 8.8.11, FortiNAC version 8.7.0 through 8.7.6, 0.5%
CVE-2022-22016 HIGH 7.0 microsoft windows_10 Windows PlayToManager Elevation of Privilege Vulnerability 0.5%
CVE-2014-6381 LOW 2.9 juniper mobile_system_software Juniper WLC devices with WLAN Software releases 8.0.x before 8.0.4, 9.0.x before 9.0.2.11, 9.0.3.x before 9.0.3.5, and 9.1.x before 9.1.1, when "Proxy ARP" or "No Broadcast" features are enabled in a clustered setup, allows remote attackers to cause a denial o 0.5%
CVE-2013-0931 MED 5.4 rsa authentication_agent_for_windows EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiratio 0.5%
CVE-2026-9071 HIGH 7.5 ibm websphere_application_server IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to c 0.5%
CVE-2026-24206 HIGH 7.3 nvidia triton_inference_server NVIDIA Triton Inference Server contains a vulnerability where an attacker could cause an authentication bypass. A successful exploit of this vulnerability might lead to escalation of privileges, denial of service, or information disclosure. 0.5%
CVE-2025-47977 HIGH 8.2 microsoft nuance_digital_engagement_platform Improper neutralization of input during web page generation ('cross-site scripting') in Nuance Digital Engagement Platform allows an unauthorized attacker to perform spoofing over a network. 0.5%
CVE-2025-47972 HIGH 8.0 microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges over a network. 0.5%
CVE-2025-37947 HIGH 8.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent out-of-bounds stream writes by validating *pos ksmbd_vfs_stream_write() did not validate whether the write offset (*pos) was within the bounds of the existing stream data leng 0.5%
CVE-2025-26644 MED 5.1 microsoft windows_10_1809 Automated recognition mechanism with inadequate detection or handling of adversarial input perturbations in Windows Hello allows an unauthorized attacker to perform spoofing locally. 0.5%
CVE-2025-24473 LOW 3.7 fortinet forticlient A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information vi 0.5%
CVE-2025-21287 HIGH 7.8 microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability 0.5%
CVE-2024-20493 MED 5.3 cisco adaptive_security_appliance_software A vulnerability in the login authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to deny further 0.5%
CVE-2023-4622 HIGH 7.8 debian debian_linux A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus there 0.5%
CVE-2023-36724 MED 5.5 microsoft windows_10_1507 Windows Power Management Service Information Disclosure Vulnerability 0.5%
CVE-2023-29359 HIGH 7.8 microsoft windows_10_1507 GDI Elevation of Privilege Vulnerability 0.5%
CVE-2023-1206 MED 5.7 fedoraproject fedora A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of 0.5%