IT
56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync

CVE Tracker

56.569 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2000-0028 LOW 2.6 microsoft ie Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the external.NavigateAndFind function. 23.1%
CVE-2000-0006 LOW 2.6 linux linux_kernel strace allows local users to read arbitrary files via memory mapped file names. 0.3%
CVE-1999-1453 LOW 2.6 microsoft internet_explorer Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the Internet WebBrowser ActiveX object. 11.2%
CVE-1999-1001 LOW 2.6 cisco cache_engine Cisco Cache Engine allows a remote attacker to gain access via a null username and password. 1.4%
CVE-1999-0871 LOW 2.6 microsoft internet_explorer Internet Explorer 4.0 and 4.01 allow a remote attacker to read files via IE's cross frame security, aka the "Cross Frame Navigate" vulnerability. 12.2%
CVE-1999-0870 LOW 2.6 microsoft internet_explorer Internet Explorer 4.01 allows remote attackers to read arbitrary files by pasting a file name into the file upload control, aka untrusted scripted paste. 12.5%
CVE-1999-0869 LOW 2.6 microsoft internet_explorer Internet Explorer 3.x to 4.01 allows a remote attacker to insert malicious content into a frame of another web site, aka frame spoofing. 17.3%
CVE-1999-0861 LOW 2.6 microsoft commercial_internet_system Race condition in the SSL ISAPI filter in IIS and other servers may leak information in plaintext. 3.2%
CVE-1999-0827 LOW 2.6 microsoft ie By default, Internet Explorer 5.0 and other versions enables the "Navigate sub-frames across different domains" option, which allows frame spoofing. 4.7%
CVE-1999-0793 LOW 2.6 microsoft internet_explorer Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet. 13.3%
CVE-1999-0749 LOW 2.6 microsoft windows_95 Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument. 8.0%
CVE-1999-0717 LOW 2.6 microsoft excel A remote attacker can disable the virus warning mechanism in Microsoft Excel 97. 5.8%
CVE-1999-0487 LOW 2.6 microsoft internet_explorer The DHTML Edit ActiveX control in Internet Explorer allows remote attackers to read arbitrary files. 13.3%
CVE-1999-0031 LOW 2.6 microsoft internet_explorer JavaScript in Internet Explorer 3.x and 4.x, and Netscape 2.x, 3.x and 4.x, allows remote attackers to monitor a user's web activities, aka the Bell Labs vulnerability. 18.3%
CVE-2026-27316 LOW 2.7 fortinet fortisandbox A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side in 0.3%
CVE-2026-24641 LOW 2.7 fortinet fortiweb A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to cras 0.4%
CVE-2025-64299 LOW 2.7 secuavail logstare_collector LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' password hashes. 0.3%
CVE-2025-59923 LOW 2.7 fortinet fortiauthenticator An improper access control vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at least read-on 0.2%
CVE-2025-58903 LOW 2.7 fortinet fortios An Unchecked Return Value vulnerability [CWE-252] in Fortinet FortiOS version 7.6.0 through 7.6.3 and before 7.4.8 API allows an authenticated user to cause a Null Pointer Dereference, crashing the http daemon via a specialy crafted request. 0.6%
CVE-2025-57823 LOW 2.7 fortinet fortiauthenticator A direct request ('forced browsing') vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow an authenticated attacker with at lea 0.2%
CVE-2025-4614 LOW 2.7 paloaltonetworks pan-os An information disclosure vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to view session tokens of users authenticated to the firewall web UI. This may allow impersonation of users whose session tokens are leaked.   0.2%
CVE-2025-31514 LOW 2.7 fortinet fortios A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 t 0.3%
CVE-2025-24474 LOW 2.7 fortinet fortianalyzer An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4. 0.3%
CVE-2025-22855 LOW 2.7 fortinet forticlientems An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code. 0.3%
CVE-2025-13459 LOW 2.7 ibm aspera_console IBM Aspera Console 3.3.0 through 3.4.8 could allow a privileged user to cause a denial of service due to improper enforcement of behavioral workflow. 0.4%