57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49571 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: check iparea_offset and ipv6_prefixes_cnt when receiving proposal msg When receiving proposal msg in server, the field iparea_offset and the field ipv6_prefixes_cnt in proposal msg | 0.6% | — |
| CVE-2024-41177 | MED 6.1 | apache zeppelin Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | 0.6% | — |
| CVE-2024-21611 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). In a Juniper Flow | 0.6% | — |
| CVE-2023-41180 | MED 5.9 | apache nifi_minifi_c\+\+ Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, | 0.6% | — |
| CVE-2023-28237 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-20186 | HIGH 8.0 | cisco ios A vulnerability in the Authentication, Authorization, and Accounting (AAA) feature of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to bypass command authorization and copy files to or from the file system of an aff | 0.6% | — |
| CVE-2022-21896 | HIGH 7.0 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-41348 | HIGH 8.0 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-15902 | MED 5.6 | debian debian_linux A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrac | 0.6% | — |
| CVE-2018-20169 | MED 6.8 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size checks during the reading of an extra descriptor, related to __usb_get_extra_descriptor in drivers/usb/core/usb.c. | 0.6% | — |
| CVE-2016-3951 | MED 4.6 | canonical ubuntu_linux Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB desc | 0.6% | — |
| CVE-2016-3689 | MED 4.6 | canonical ubuntu_linux The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface. | 0.6% | — |
| CVE-2016-2187 | MED 4.6 | canonical ubuntu_linux The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | 0.6% | — |
| CVE-2026-55976 | CRIT 9.1 | apache hive Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url t | 0.6% | — |
| CVE-2025-53774 | MED 6.5 | microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability | 0.6% | — |
| CVE-2025-38566 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sunrpc: fix handling of server side tls alerts Scott Mayhew discovered a security exploit in NFS over TLS in tls_alert_recv() due to its assumption it can read data from the msg iterator's k | 0.6% | — |
| CVE-2025-29796 | MED 4.7 | microsoft edge User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-21374 | MED 5.5 | microsoft windows_10_1507 Windows CSC Service Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-20691 | MED 4.7 | microsoft windows_10_1507 Windows Themes Information Disclosure Vulnerability | 0.6% | — |
| CVE-2023-37934 | MED 4.3 | fortinet fortipam An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perform a denial of service attack via sending crafted HTTP or HTTPS requests in a high frequency. | 0.6% | — |
| CVE-2023-31436 | HIGH 7.8 | linux linux_kernel qfq_change_class in net/sched/sch_qfq.c in the Linux kernel before 6.2.13 allows an out-of-bounds write because lmax can exceed QFQ_MIN_LMAX. | 0.6% | — |
| CVE-2023-0140 | MED 6.5 | google chrome Inappropriate implementation in in File System API in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Low) | 0.6% | — |
| CVE-2023-0139 | MED 6.5 | google chrome Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 109.0.5414.74 allowed a remote attacker to bypass download restrictions via a crafted HTML page. (Chromium security severity: Low) | 0.6% | — |
| CVE-2022-48697 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix a use-after-free Fix the following use-after-free complaint triggered by blktests nvme/004: BUG: KASAN: user-memory-access in blk_mq_complete_request_remote+0xac/0x350 Read of si | 0.6% | — |
| CVE-2022-41123 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |