57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-22245 | MED 5.9 | broadcom vmware_nsx VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. | 0.3% | — |
| CVE-2025-21350 | MED 5.9 | microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability | 2.1% | — |
| CVE-2025-21242 | MED 5.9 | microsoft windows_10_1507 Windows Kerberos Information Disclosure Vulnerability | 1.6% | — |
| CVE-2025-21225 | MED 5.9 | microsoft windows_server_2016 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability | 1.6% | — |
| CVE-2025-20157 | MED 5.9 | cisco catalyst_sd-wan_manager A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation o | 0.3% | — |
| CVE-2025-13916 | MED 5.9 | ibm aspera_shares IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information | 0.2% | — |
| CVE-2025-13219 | MED 5.9 | ibm aspera_orchestrator IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. | 0.3% | — |
| CVE-2025-12436 | MED 5.9 | google chrome Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security sev | 0.2% | — |
| CVE-2024-55912 | MED 5.9 | ibm concert IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.2% | — |
| CVE-2024-51456 | MED 5.9 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks. | 0.3% | — |
| CVE-2024-50568 | MED 5.9 | fortinet fortios A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attack | 0.4% | — |
| CVE-2024-49023 | MED 5.9 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.5% | — |
| CVE-2024-47506 | MED 5.9 | juniper junos A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a large amount of traffic is processed by ATP Cloud inspection | 0.3% | — |
| CVE-2024-47494 | MED 5.9 | juniper junos A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during | 0.4% | — |
| CVE-2024-47491 | MED 5.9 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). When a BGP UPDATE with malfo | 0.6% | — |
| CVE-2024-46544 | MED 5.9 | apache tomcat_connectors Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Con | 0.3% | — |
| CVE-2024-45671 | MED 5.9 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.2% | — |
| CVE-2024-45643 | MED 5.9 | ibm security_qradar_edr IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information. | 0.2% | — |
| CVE-2024-45627 | MED 5.9 | apache linkis In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, the par | 0.3% | — |
| CVE-2024-43587 | MED 5.9 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-43178 | MED 5.9 | ibm concert IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.1% | — |
| CVE-2024-41909 | MED 5.9 | apache mina_sshd Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client a | 0.6% | — |
| CVE-2024-41763 | MED 5.9 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | 0.2% | — |
| CVE-2024-41164 | MED 5.9 | f5 big-ip_access_policy_manager When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support ( | 0.4% | — |
| CVE-2024-39746 | MED 5.9 | ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensi | 0.3% | — |