57.415 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.415 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21347 | MED 6.0 | microsoft windows_10_1507 Windows Deployment Services Denial of Service Vulnerability | 0.6% | — |
| CVE-2025-21195 | MED 6.0 | microsoft azure_service_fabric Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2025-21188 | MED 6.0 | microsoft azure_network_watcher Azure Network Watcher VM Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-20338 | MED 6.0 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insu | 0.2% | — |
| CVE-2025-20308 | MED 6.0 | cisco spaces_connector A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient restrictions during the executi | 0.2% | — |
| CVE-2025-20278 | MED 6.0 | cisco finesse A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to i | 0.2% | — |
| CVE-2025-20178 | MED 6.0 | cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics could allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. This vuln | 0.3% | — |
| CVE-2025-20155 | MED 6.0 | cisco ios_xe A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient input validation of the bootstrap file that is read by t | 0.2% | — |
| CVE-2025-20119 | MED 6.0 | cisco application_policy_infrastructure_controller A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative | 0.1% | — |
| CVE-2024-5661 | MED 6.0 | citrix hypervisor An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive. | 0.2% | — |
| CVE-2024-40593 | MED 6.0 | fortinet fortianalyzer A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.5, FortiMan | 0.1% | — |
| CVE-2024-36508 | MED 6.0 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an | 0.2% | — |
| CVE-2024-29195 | MED 6.0 | microsoft azure_c_shared_utility The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocatio | 5.0% | — |
| CVE-2024-26894 | MED 6.0 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() After unregistering the CPU idle device, the memory associated with it is not freed, leading to a memory leak: unreferen | 0.3% | — |
| CVE-2024-26843 | MED 6.0 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: efi: runtime: Fix potential overflow of soft-reserved region size md_size will have been narrowed if we have >= 4GB worth of pages in a soft-reserved region. | 0.2% | — |
| CVE-2024-2552 | MED 6.0 | paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions in the management plane and delete files on the firewall. | 0.5% | — |
| CVE-2024-23976 | MED 6.0 | f5 big-ip_access_policy_manager When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (Eo | 0.2% | — |
| CVE-2024-20492 | MED 6.0 | cisco telepresence_video_communication_server A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker | 0.6% | — |
| CVE-2024-20485 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. Administrator-level p | 0.2% | — |
| CVE-2024-20469 | MED 6.0 | cisco identity_services_engine A vulnerability in specific CLI commands in Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, | 0.5% | — |
| CVE-2024-20461 | MED 6.0 | cisco ata_191_firmware A vulnerability in the CLI of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, local attacker with high privileges to execute arbitrary commands as the root user. This vulnerability exists because CLI input is not pr | 0.2% | — |
| CVE-2024-20399 | MED 6.0 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insu | 4.3% | |
| CVE-2024-20359 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, l | 19.4% | |
| CVE-2024-20358 | MED 6.0 | cisco adaptive_security_appliance_software A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the und | 0.7% | — |
| CVE-2024-20306 | MED 6.0 | cisco ios_xe A vulnerability in the Unified Threat Defense (UTD) configuration CLI of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying host operating system. To exploit this vulnerability, an attacke | 0.2% | — |