IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-3395 MED 6.8 cisco content_security_management_appliance Cross-site request forgery (CSRF) vulnerability in the web framework on Cisco IronPort Web Security Appliance (WSA) devices, Email Security Appliance (ESA) devices, and Content Security Management Appliance (SMA) devices allows remote attackers to hijack the a 0.6%
CVE-2013-1153 MED 6.8 cisco prime_infrastructure Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676. 0.6%
CVE-2012-1316 MED 5.9 cisco ironport_web_security_appliance Cisco IronPort Web Security Appliance does not check for certificate revocation which could lead to MITM attacks 0.6%
CVE-2005-0504 MED 4.6 linux linux_kernel Buffer overflow in the MoxaDriverIoctl function for the moxa serial driver (moxa.c) in Linux 2.2.x, 2.4.x, and 2.6.x before 2.6.22 allows local users to execute arbitrary code via a certain modified length value. 0.6%
CVE-2026-65806 MED 6.5 microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network. 0.6%
CVE-2026-57977 HIGH 7.1 microsoft edge_chromium Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.6%
CVE-2026-53571 HIGH 7.5 vitejs vite Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s dev server denies direct access to sensitive files through serv 0.6%
CVE-2026-44615 MED 6.5 apache zeppelin Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths.                   Z 0.6%
CVE-2026-23652 CRIT 10.0 microsoft power_pages Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2023-47152 MED 5.9 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an insecure cryptographic algorithm and to information disclosure in stack trace under exceptional conditions. 0.6%
CVE-2022-23298 HIGH 7.0 microsoft windows_10 Windows NT OS Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2022-23288 HIGH 7.0 microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability 0.6%
CVE-2022-23287 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.6%
CVE-2020-27171 MED 6.0 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigat 0.6%
CVE-2018-20669 HIGH 7.8 canonical ubuntu_linux An issue where a provided address with access_ok() is not checked was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL function call to over 0.6%
CVE-2013-1848 MED 6.2 linux linux_kernel fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application. 0.6%
CVE-2026-10816 HIGH 7.5 citrix netscaler_application_delivery_controller Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled 0.6%
CVE-2025-50159 HIGH 7.3 microsoft windows_10_1507 Use after free in Remote Access Point-to-Point Protocol (PPP) EAP-TLS allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-49201 HIGH 8.1 fortinet fortipam A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiSwitchManager 7.2.0 through 7.2.4 allows attacker to 0.6%
CVE-2025-48002 MED 5.7 microsoft windows_11_24h2 Integer overflow or wraparound in Windows Hyper-V allows an authorized attacker to disclose information over an adjacent network. 0.6%
CVE-2024-50563 HIGH 7.3 fortinet fortianalyzer A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiAnalyzer Cloud versions 7.4.1 through 7.4.3, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 through 7.4.3, FortiManager Cloud versions 0.6%
CVE-2024-49054 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.6%
CVE-2022-38003 HIGH 7.8 microsoft windows_10 Windows Resilient File System Elevation of Privilege 0.6%
CVE-2022-37980 HIGH 7.8 microsoft windows_10 Windows DHCP Client Elevation of Privilege Vulnerability 0.6%
CVE-2022-30994 HIGH 7.5 acronis cyber_protect Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240 0.6%