57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-25037 | MED 4.3 | ibm cognos_controller IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. | 0.6% | — |
| CVE-2023-28298 | MED 5.5 | microsoft windows_10_1607 Windows Kernel Denial of Service Vulnerability | 0.6% | — |
| CVE-2022-38604 | HIGH 7.3 | wacom driver Wacom Driver 6.3.46-1 for Windows and lower was discovered to contain an arbitrary file deletion vulnerability. | 0.6% | — |
| CVE-2022-22450 | LOW 3.8 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 could allow a privileged user to upload a malicious file by bypassing extension security in an HTTP request. IBM X-Force ID: 224916. | 0.6% | — |
| CVE-2021-33033 | HIGH 7.8 | linux linux_kernel The Linux kernel before 5.11.14 has a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled, aka CID-ad5d07f4a9cd. This leads to writing an arbitrary value. | 0.6% | — |
| CVE-2020-3505 | MED 6.5 | cisco 8000p_ip_camera_firmware A vulnerability in the Cisco Discovery Protocol of Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to cause a memory leak, which could lead to a denial of service (DoS) condition on an affected device. The vuln | 0.6% | — |
| CVE-2020-3114 | HIGH 8.8 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insuffici | 0.6% | — |
| CVE-2020-25211 | MED 6.0 | debian debian_linux In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netli | 0.6% | — |
| CVE-2018-21008 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel before 4.16.7. A use-after-free can be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c. | 0.6% | — |
| CVE-2018-14734 | HIGH 7.8 | canonical ubuntu_linux drivers/infiniband/core/ucma.c in the Linux kernel through 4.17.11 allows ucma_leave_multicast to access a certain data structure after a cleanup step in ucma_process_join, which allows attackers to cause a denial of service (use-after-free). | 0.6% | — |
| CVE-2018-0446 | HIGH 8.8 | cisco network_level_service A vulnerability in the web-based management interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerabil | 0.6% | — |
| CVE-2018-0445 | HIGH 8.8 | cisco packaged_contact_center_enterprise A vulnerability in the web-based management interface of Cisco Packaged Contact Center Enterprise could allow an unauthenticated, remote attacker to conduct a CSRF attack and perform arbitrary actions on an affected device. The vulnerability is due to insuffic | 0.6% | — |
| CVE-2017-10620 | HIGH 7.4 | juniper junos Juniper Networks Junos OS on SRX series devices do not verify the HTTPS server certificate before downloading anti-virus updates. This may allow a man-in-the-middle attacker to inject bogus signatures to cause service disruptions or make the device not detect | 0.6% | — |
| CVE-2015-5307 | MED 4.9 | canonical ubuntu_linux The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #AC (aka Alignment Check) exceptions, related to svm.c and vmx.c. | 0.6% | — |
| CVE-2013-4591 | MED 6.2 | linux linux_kernel Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system c | 0.6% | — |
| CVE-2013-1141 | MED 6.1 | cisco wireless_lan_controller The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) via crafted mDNS packets, a | 0.6% | — |
| CVE-2012-5616 | LOW 1.5 | apache cloudstack Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, ( | 0.6% | — |
| CVE-2011-4127 | MED 4.6 | linux linux_kernel The Linux kernel before 3.2.2 does not properly restrict SG_IO ioctl calls, which allows local users to bypass intended restrictions on disk read and write operations by sending a SCSI command to (1) a partition block device or (2) an LVM volume. | 0.6% | — |
| CVE-2026-11311 | HIGH 8.1 | f5 nginx_gateway_fabric When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serve | 0.6% | — |
| CVE-2025-55247 | HIGH 7.3 | microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-48804 | MED 6.8 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.6% | — |
| CVE-2025-21357 | MED 6.7 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2024-47749 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Added NULL check for lookup_atid The lookup_atid() function can return NULL if the ATID is invalid or does not exist in the identifier table, which could lead to dereferencing a | 0.6% | — |
| CVE-2024-38246 | HIGH 7.0 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-28924 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |