57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-50154 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink(). Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(). """ We are seeing a use-after-free from a bpf prog at | 0.6% | — |
| CVE-2024-45478 | MED 4.8 | apache ranger Stored XSS vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | 0.6% | — |
| CVE-2023-40250 | HIGH 8.8 | hancom hcell Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Hancom HCell on Windows allows Overflow Buffers.This issue affects HCell: 12.0.0.893. | 0.6% | — |
| CVE-2023-27875 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 5.0.4 could allow a user to change other user's credentials due to improper access controls. IBM X-Force ID: 249847. | 0.6% | — |
| CVE-2023-20246 | MED 5.8 | cisco ios_xe Multiple Cisco products are affected by a vulnerability in Snort access control policies that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. This vulnerability is due to a logic error that occurs wh | 0.6% | — |
| CVE-2022-41329 | MED 5.3 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to | 0.6% | — |
| CVE-2021-21987 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be | 0.6% | — |
| CVE-2019-19689 | HIGH 7.8 | trendmicro housecall_for_home_networks Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses. | 0.6% | — |
| CVE-2019-1826 | MED 6.8 | cisco aironet_access_point_firmware A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input v | 0.6% | — |
| CVE-2018-1897 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462. | 0.6% | — |
| CVE-2016-6444 | HIGH 8.8 | cisco meeting_server A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. | 0.6% | — |
| CVE-2026-8859 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest component. A path traversal vulnerability exists when the "Save to File" feature is enabl | 0.6% | — |
| CVE-2026-7667 | HIGH 8.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling arbitrary fi | 0.6% | — |
| CVE-2026-69400 | CRIT 9.6 | microsoft azure_logic_apps Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-62889 | HIGH 8.1 | microsoft windows_10_1607 Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-41043 | MED 6.5 | apache activemq Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache ActiveMQ, Apache ActiveMQ Web. An authenticated attacker can show malicious content when browsing queues in the web console by overriding the content type to | 0.6% | — |
| CVE-2026-23450 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix NULL dereference and UAF in smc_tcp_syn_recv_sock() Syzkaller reported a panic in smc_tcp_syn_recv_sock() [1]. smc_tcp_syn_recv_sock() is called in the TCP receive path (softir | 0.6% | — |
| CVE-2026-10817 | HIGH 7.5 | citrix netscaler_application_delivery_controller Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler | 0.6% | — |
| CVE-2025-33075 | HIGH 7.8 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-22222 | HIGH 7.7 | vmware aria_operations VMware Aria Operations contains an information disclosure vulnerability. A malicious user with non-administrative privileges may exploit this vulnerability to retrieve credentials for an outbound plugin if a valid service credential ID is known. | 0.6% | — |
| CVE-2024-20695 | MED 5.7 | microsoft skype_for_business_server Skype for Business Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-49770 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ceph: avoid putting the realm twice when decoding snaps fails When decoding the snaps fails it maybe leaving the 'first_realm' and 'realm' pointing to the same snaprealm memory. And then it' | 0.6% | — |
| CVE-2022-23255 | MED 5.9 | microsoft onedrive Microsoft OneDrive for Android Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2019-15923 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel before 5.0.9. There is a NULL pointer dereference for a cd data structure if alloc_disk fails in drivers/block/paride/pf.c. | 0.6% | — |
| CVE-2018-0029 | MED 5.7 | juniper junos While experiencing a broadcast storm, placing the fxp0 interface into promiscuous mode via the 'monitor traffic interface fxp0' can cause the system to crash and restart (vmcore). This issue only affects Junos OS 15.1 and later releases, and affects both singl | 0.6% | — |