57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-6382 | MED 4.0 | linux linux_kernel Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_AT | 0.6% | — |
| CVE-2006-2935 | MED 4.6 | canonical ubuntu_linux The dvd_read_bca function in the DVD handling code in drivers/cdrom/cdrom.c in Linux kernel 2.2.16, and later versions, assigns the wrong value to a length variable, which allows local users to execute arbitrary code via a crafted USB Storage device that trigg | 0.6% | — |
| CVE-2026-69876 | HIGH 8.0 | microsoft windows_10_1607 Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network. | 0.6% | — |
| CVE-2026-50683 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network. | 0.6% | — |
| CVE-2025-60714 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows OLE allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-58903 | LOW 2.7 | fortinet fortios An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request. | 0.6% | — |
| CVE-2024-5911 | MED 4.9 | paloaltonetworks pan-os An arbitrary file upload vulnerability in Palo Alto Networks Panorama software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and crash the Panorama. Repeated attacks eventually cause the Panorama | 0.6% | — |
| CVE-2024-50145 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: octeon_ep: Add SKB allocation failures handling in __octep_oq_process_rx() build_skb() returns NULL in case of a memory allocation failure so handle it inside __octep_oq_process_rx() to avoi | 0.6% | — |
| CVE-2024-38188 | HIGH 7.1 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-3383 | HIGH 7.4 | paloaltonetworks pan-os A vulnerability in how Palo Alto Networks PAN-OS software processes data received from Cloud Identity Engine (CIE) agents enables modification of User-ID groups. This impacts user access to network resources where users may be inappropriately denied or allowed | 0.6% | — |
| CVE-2024-26213 | HIGH 7.0 | microsoft windows_server_2022_23h2 Microsoft Brokering File System Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-20381 | HIGH 8.8 | cisco ios_xr A vulnerability in the JSON-RPC API feature in Cisco Crosswork Network Services Orchestrator (NSO) and ConfD that is used by the web-based management interfaces of Cisco Optical Site Manager and Cisco RV340 Dual WAN Gigabit VPN Routers could allow an authentic | 0.6% | — |
| CVE-2024-1545 | MED 5.9 | wolfssl wolfssl Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in WolfSSL wolfssl5.6.6 on Linux/Windows allows remote attacker co-resides in the same system with a victim process to disclose information and escalate privileges vi | 0.6% | — |
| CVE-2023-36914 | MED 5.5 | microsoft windows_10_21h2 Windows Smart Card Resource Management Server Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-36904 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-26205 | HIGH 8.1 | fortinet fortiadc An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a spe | 0.6% | — |
| CVE-2022-24960 | MED 6.5 | pdftron pdftron A use after free vulnerability was discovered in PDFTron SDK version 9.2.0. A crafted PDF can overwrite RIP with data previously allocated on the heap. This issue affects: PDFTron PDFTron SDK 9.2.0 on OSX; 9.2.0 on Linux; 9.2.0 on Windows. | 0.6% | — |
| CVE-2021-1527 | MED 5.3 | cisco webex_player A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the affected software to terminate or to gain access to memory state information that is related to the vulnerable application. The vulnerability is due to insufficien | 0.6% | — |
| CVE-2020-6648 | MED 5.3 | fortinet fortios A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an authenticated attacker to obtain sensitive information such as users passwords by co | 0.6% | — |
| CVE-2016-2064 | HIGH 7.8 | linux linux_kernel sound/soc/msm/qdsp6v2/msm-audio-effects-q6-v2.c in the MSM QDSP6 audio driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (buffer | 0.6% | — |
| CVE-2013-3451 | MED 6.8 | cisco unified_communications_manager Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Unified Communications Manager (Unified CM) allow remote attackers to hijack the authentication of arbitrary users for requests that perform arbitrary Unified CM operations, aka Bug ID CSCui13 | 0.6% | — |
| CVE-2013-3450 | MED 6.8 | cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the User WebDialer page in Cisco Unified Communications Manager (Unified CM) allows remote attackers to hijack the authentication of arbitrary users for requests that dial calls, aka Bug ID CSCui13028. | 0.6% | — |
| CVE-2013-3420 | MED 6.8 | cisco identity_services_engine Cross-site request forgery (CSRF) vulnerability in the web framework on the Cisco Identity Services Engine (ISE) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh25506. | 0.6% | — |
| CVE-2013-3397 | MED 6.8 | cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability component in Cisco Unified Communications Manager (CUCM) allows remote attackers to hijack the authentication of arbitrary users for requests that perform Unified Serviceability acti | 0.6% | — |
| CVE-2013-3395 | MED 6.8 | cisco content_security_management_appliance Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the a | 0.6% | — |