IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2023-38363 MED 4.3 ibm cics_tx IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be 0.6%
CVE-2023-38150 HIGH 7.8 microsoft windows_11_21h2 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2023-21764 HIGH 7.8 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 0.6%
CVE-2022-38457 MED 6.3 linux linux_kernel A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the 0.6%
CVE-2022-30610 MED 4.5 ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that anothe 0.6%
CVE-2021-4454 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: j1939: fix errant WARN_ON_ONCE in j1939_session_deactivate The conclusion "j1939_session_deactivate() should be called with a session ref-count of at least 2" is incorrect. In some conc 0.6%
CVE-2021-41019 LOW 3.5 fortinet fortios An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials. 0.6%
CVE-2021-28314 HIGH 7.8 microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability 0.6%
CVE-2020-27152 MED 5.5 linux linux_kernel An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9. 0.6%
CVE-2019-11396 HIGH 7.8 avira free_security_suite An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that c 0.6%
CVE-2018-25015 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8. 0.6%
CVE-2017-12283 MED 6.1 cisco aironet_3800_firmware A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device, aka Denial of Service. The vul 0.6%
CVE-2017-12282 MED 6.1 cisco wireless_lan_controller_software A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN Controllers could allow an unauthenticated, Layer 2 RF-adjacent attacker to cause an affected device to restart unexpectedly, resulting in 0.6%
CVE-2015-8785 MED 6.2 linux linux_kernel The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov. 0.6%
CVE-2026-69519 HIGH 8.6 microsoft azure_stack_hci Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. 0.6%
CVE-2026-21222 MED 5.5 microsoft windows_10_1607 Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-47979 MED 5.5 microsoft windows_server_2022_23h2 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. 0.6%
CVE-2025-21278 MED 6.2 microsoft windows_10_1507 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability 0.6%
CVE-2024-28907 HIGH 7.8 microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability 0.6%
CVE-2023-20195 MED 4.7 cisco identity_services_engine Two vulnerabilities in Cisco ISE could allow an authenticated, remote attacker to upload arbitrary files to an affected device. To exploit these vulnerabilities, an attacker must have valid Administrator credentials on the affected device. These vulnerabilitie 0.6%
CVE-2022-29138 HIGH 7.0 microsoft windows_server Windows Clustered Shared Volume Elevation of Privilege Vulnerability 0.6%
CVE-2022-20861 CRIT 9.8 cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit 0.6%
CVE-2020-3968 HIGH 8.2 vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.5), and Fusion (11.x before 11.5.5) contain an out-of-bounds write vulnerability in the USB 3.0 controller (xH 0.6%
CVE-2020-13974 HIGH 7.8 canonical ubuntu_linux An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to 0.6%
CVE-2019-17388 HIGH 7.8 aviatrix vpn_client Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. 0.6%