57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21227 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2025-21226 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-50569 | MED 6.6 | fortinet fortiweb A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input. | 1.8% | — |
| CVE-2024-49111 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-49109 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49101 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-49094 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-49081 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-48890 | MED 6.6 | fortinet fortisoar_imap_connector An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSOAR IMAP connector version 3.5.7 and below may allow an authenticated attacker to execute unauthorized code or commands via a specific | 1.1% | — |
| CVE-2024-47570 | MED 6.6 | fortinet fortios An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7.4.0 through 7.4.3, 7.2.0 through 7.2.11; FortiPAM 1.4 all versions, 1.3 all versions, 1.2 all versio | 0.4% | — |
| CVE-2024-43480 | MED 6.6 | microsoft azure_service_fabric Azure Service Fabric for Linux Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-39512 | MED 6.6 | juniper junos_os_evolved An Improper Physical Access Control vulnerability in the console port control of Juniper Networks Junos OS Evolved allows an attacker with physical access to the device to get access to a user account. When the console cable is disconnected, the logged in use | 0.2% | — |
| CVE-2024-38049 | MED 6.6 | microsoft windows_10_1507 Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-35275 | MED 6.6 | fortinet fortianalyzer A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http request | 0.8% | — |
| CVE-2024-26201 | MED 6.6 | microsoft intune_company_portal Microsoft Intune Linux Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-25051 | MED 6.6 | ibm jazz_reporting_service IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system. | 0.4% | — |
| CVE-2024-20666 | MED 6.6 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 3.1% | — |
| CVE-2024-20655 | MED 6.6 | microsoft windows_server_2008 Microsoft Online Certificate Status Protocol (OCSP) Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2024-20294 | MED 6.6 | cisco firepower_extensible_operating_system A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is d | 0.3% | — |
| CVE-2024-0841 | MED 6.6 | linux linux_kernel A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system. | 0.3% | — |
| CVE-2024-0607 | MED 6.6 | fedoraproject fedora A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so e | 0.2% | — |
| CVE-2024-0008 | MED 6.6 | paloaltonetworks pan-os Web sessions in the management interface in Palo Alto Networks PAN-OS software do not expire in certain situations, making it susceptible to unauthorized access. | 0.5% | — |
| CVE-2023-52819 | MED 6.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd: Fix UBSAN array-index-out-of-bounds for Polaris and Tonga For pptable structs that use flexible array sizes, use flexible arrays. | 0.2% | — |
| CVE-2023-4996 | MED 6.6 | netskope netskope Netskope was made aware of a security vulnerability in its NSClient product for version 100 & prior where a malicious non-admin user can disable the Netskope client by using a specially-crafted package. The root cause of the problem was a user control code whe | 0.4% | — |
| CVE-2023-47706 | MED 6.6 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. | 0.8% | — |