IT
57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.411 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-22245 MED 5.9 broadcom vmware_nsx VMware NSX contains a stored Cross-Site Scripting (XSS) vulnerability in the router port due to improper input validation. 0.3%
CVE-2025-21350 MED 5.9 microsoft windows_10_1507 Windows Kerberos Denial of Service Vulnerability 2.1%
CVE-2025-21242 MED 5.9 microsoft windows_10_1507 Windows Kerberos Information Disclosure Vulnerability 1.6%
CVE-2025-21225 MED 5.9 microsoft windows_server_2016 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability 1.6%
CVE-2025-20157 MED 5.9 cisco catalyst_sd-wan_manager A vulnerability in certificate validation processing of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability is due to improper validation o 0.3%
CVE-2025-13916 MED 5.9 ibm aspera_shares IBM Aspera Shares 1.9.9 through 1.11.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information 0.2%
CVE-2025-13219 MED 5.9 ibm aspera_orchestrator IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. 0.3%
CVE-2025-12436 MED 5.9 google chrome Policy bypass in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security sev 0.2%
CVE-2024-55912 MED 5.9 ibm concert IBM Concert Software 1.0.0 through 1.0.5 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0.2%
CVE-2024-51456 MED 5.9 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks. 0.3%
CVE-2024-50568 MED 5.9 fortinet fortios A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 through 7.4.3, 7.2.0 through 7.2.9 and before 7.0.16 allows an unauthenticated attack 0.4%
CVE-2024-49023 MED 5.9 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.5%
CVE-2024-47506 MED 5.9 juniper junos A Deadlock vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When a large amount of traffic is processed by ATP Cloud inspection 0.3%
CVE-2024-47494 MED 5.9 juniper junos A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in the AgentD process of Juniper Networks Junos OS allows an attacker who is already causing impact to established sessions which generates counter changes picked up by the AgentD process during 0.4%
CVE-2024-47491 MED 5.9 juniper junos An Improper Handling of Exceptional Conditions vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to cause Denial of Service (DoS). When a BGP UPDATE with malfo 0.6%
CVE-2024-46544 MED 5.9 apache tomcat_connectors Incorrect Default Permissions vulnerability in Apache Tomcat Connectors allows local users to view and modify shared memory containing mod_jk configuration which may lead to information disclosure and/or denial of service. This issue affects Apache Tomcat Con 0.3%
CVE-2024-45671 MED 5.9 ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.5, 10.0.6, 10.0.7, and 10.0.8 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0.2%
CVE-2024-45643 MED 5.9 ibm security_qradar_edr IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information. 0.2%
CVE-2024-45627 MED 5.9 apache linkis In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will allow the attacker to read arbitrary files from the Linkis server. Therefore, the par 0.3%
CVE-2024-43587 MED 5.9 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.9%
CVE-2024-43178 MED 5.9 ibm concert IBM Concert 1.0.0 through 2.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0.1%
CVE-2024-41909 MED 5.9 apache mina_sshd Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client a 0.6%
CVE-2024-41763 MED 5.9 ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. 0.2%
CVE-2024-41164 MED 5.9 f5 big-ip_access_policy_manager When TCP profile with Multipath TCP enabled (MPTCP) is configured on a Virtual Server, undisclosed traffic along with conditions beyond the attackers control can cause TMM to terminate. Note: Software versions which have reached End of Technical Support ( 0.4%
CVE-2024-39746 MED 5.9 ibm sterling_connect_direct_web_services IBM Sterling Connect:Direct Web Services 6.0, 6.1, 6.2, and 6.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensi 0.3%