57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-53678 | HIGH 8.8 | apache vcl Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache VCL. Users can modify form data submitted when requesting a new Block Allocation such that a SELECT SQL statement is modified. The data returned by the | 0.6% | — |
| CVE-2024-50285 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: check outstanding simultaneous SMB operations If Client send simultaneous SMB operations to ksmbd, It exhausts too much memory through the "ksmbd_work_cache”. It will cause OOM issue. | 0.6% | — |
| CVE-2024-47491 | MED 5.9 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). When a BGP UPDATE with malfo | 0.6% | — |
| CVE-2024-26011 | MED 5.3 | fortinet fortimanager A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version 7.4.0 thr | 0.6% | — |
| CVE-2024-20474 | MED 4.3 | cisco anyconnect_secure_mobility_client A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflo | 0.6% | — |
| CVE-2023-21714 | MED 5.5 | microsoft 365_apps Microsoft Office Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-42721 | MED 5.5 | debian debian_linux A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code. | 0.6% | — |
| CVE-2022-27772 | HIGH 7.8 | vmware spring_boot spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only | 0.6% | — |
| CVE-2021-47137 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: lantiq: fix memory corruption in RX ring In a situation where memory allocation or dma mapping fails, an invalid address is programmed into the descriptor. This can lead to memory corru | 0.6% | — |
| CVE-2012-4073 | MED 5.8 | cisco unified_computing_system The KVM subsystem in the client in Cisco Unified Computing System (UCS) does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers, and read or modify KVM data, via a crafted certificate, aka Bug ID CSCte9033 | 0.6% | — |
| CVE-2025-54908 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-32720 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2025-21234 | HIGH 7.8 | microsoft windows_10_21h2 Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21184 | HIGH 7.0 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.6% | — |
| CVE-2024-26834 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_flow_offload: release dst in case direct xmit path is used Direct xmit does not use it since it calls dev_queue_xmit() to send packets, hence it calls dst_release(). kmemleak | 0.6% | — |
| CVE-2024-26768 | HIGH 7.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: LoongArch: Change acpi_core_pic[NR_CPUS] to acpi_core_pic[MAX_CORE_PIC] With default config, the value of NR_CPUS is 64. When HW platform has more then 64 cpus, system will crash on these pl | 0.6% | — |
| CVE-2023-28292 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-23402 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-23401 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-21809 | HIGH 7.8 | microsoft defender_security_intelligence_updates Microsoft Defender for Endpoint Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2022-22329 | MED 4.3 | ibm control_desk IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent | 0.6% | — |
| CVE-2022-20802 | MED 5.4 | cisco enterprise_chat_and_email A vulnerability in the web interface of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of | 0.6% | — |
| CVE-2021-23047 | MED 5.3 | f5 big-ip_access_policy_manager On version 16.x before 16.1.0, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.3, and all versions of 13.1.x, 12.1.x and 11.6.x, when BIG-IP APM performs Online Certificate Status Protocol (OCSP) verification of a certificate that contains Authority Information A | 0.6% | — |
| CVE-2008-2100 | HIGH 7.2 | vmware ace Multiple buffer overflows in VIX API 1.1.x before 1.1.4 build 93057 on VMware Workstation 5.x and 6.x, VMware Player 1.x and 2.x, VMware ACE 2.x, VMware Server 1.x, VMware Fusion 1.x, VMware ESXi 3.5, and VMware ESX 3.0.1 through 3.5 allow guest OS users to ex | 0.6% | — |
| CVE-2026-59245 | HIGH 8.1 | apache apache-airflow-providers-fab In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs | 0.6% | — |