57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-11584 | MED 6.1 | plesk onyx A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | 0.9% | — |
| CVE-2020-1996 | MED 5.3 | paloaltonetworks pan-os A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fa | 0.9% | — |
| CVE-2016-2853 | HIGH 7.8 | linux linux_kernel The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. | 0.9% | — |
| CVE-2015-6359 | MED 6.1 | cisco ios The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND | 0.9% | — |
| CVE-2026-25172 | HIGH 8.0 | microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-54113 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-53131 | HIGH 8.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2025-50163 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-36929 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb | 0.9% | — |
| CVE-2024-21429 | MED 6.8 | microsoft windows_10_1507 Windows USB Hub Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-35899 | HIGH 7.8 | asus aura_ready_game_software_development_kit There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file. | 0.9% | — |
| CVE-2022-30302 | MED 6.5 | fortinet fortideceptor Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlyi | 0.9% | — |
| CVE-2022-0807 | MED 6.5 | google chrome Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. | 0.9% | — |
| CVE-2022-23025 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. No | 0.9% | — |
| CVE-2022-23024 | HIGH 7.5 | f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cau | 0.9% | — |
| CVE-2016-4118 | HIGH 7.8 | adobe connect Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors. | 0.9% | — |
| CVE-2026-42903 | MED 6.5 | microsoft windows_10_1607 Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. | 0.9% | — |
| CVE-2025-54917 | MED 4.3 | microsoft windows_10_1507 Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2023-45284 | MED 5.3 | golang go On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With f | 0.9% | — |
| CVE-2023-27871 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. | 0.9% | — |
| CVE-2022-20918 | HIGH 7.5 | cisco firepower_services_software_for_asa A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Preventi | 0.9% | — |
| CVE-2021-44226 | HIGH 7.3 | razer synapse Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have pla | 0.9% | — |
| CVE-2021-24010 | HIGH 8.1 | fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. | 0.9% | — |
| CVE-2021-33767 | HIGH 8.2 | microsoft open_enclave_software_development_kit Open Enclave SDK Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-0697 | HIGH 7.8 | microsoft office_365_proplus An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place | 0.9% | — |