IT
57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.613 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-11584 MED 6.1 plesk onyx A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. 0.9%
CVE-2020-1996 MED 5.3 paloaltonetworks pan-os A missing authorization vulnerability in the management server component of PAN-OS Panorama allows a remote unauthenticated user to inject messages into the management server ms.log file. This vulnerability can be leveraged to obfuscate an ongoing attack or fa 0.9%
CVE-2016-2853 HIGH 7.8 linux linux_kernel The aufs module for the Linux kernel 3.x and 4.x does not properly restrict the mount namespace, which allows local users to gain privileges by mounting an aufs filesystem on top of a FUSE filesystem, and then executing a crafted setuid program. 0.9%
CVE-2015-6359 MED 6.1 cisco ios The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in Cisco IOS 15.3(3)S0.1 on ASR devices mishandles internal tables, which allows remote attackers to cause a denial of service (memory consumption or device crash) via a flood of crafted ND 0.9%
CVE-2026-25172 HIGH 8.0 microsoft windows_server_2012 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-54113 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-53131 HIGH 8.8 microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-50163 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2024-36929 HIGH 7.5 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: core: reject skb_copy(_expand) for fraglist GSO skbs SKB_GSO_FRAGLIST skbs must not be linearized, otherwise they become invalid. Return NULL if such an skb is passed to skb_copy or skb 0.9%
CVE-2024-21429 MED 6.8 microsoft windows_10_1507 Windows USB Hub Driver Remote Code Execution Vulnerability 0.9%
CVE-2022-35899 HIGH 7.8 asus aura_ready_game_software_development_kit There is an unquoted service path in ASUSTeK Aura Ready Game SDK service (GameSDK.exe) 1.0.0.4. This might allow a local user to escalate privileges by creating a %PROGRAMFILES(X86)%\ASUS\GameSDK.exe file. 0.9%
CVE-2022-30302 MED 6.5 fortinet fortideceptor Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 through 4.0.1 may allow a remote and authenticated attacker to retrieve and delete arbitrary files from the underlyi 0.9%
CVE-2022-0807 MED 6.5 google chrome Inappropriate implementation in Autofill in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. 0.9%
CVE-2022-23025 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.1, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, when a SIP ALG profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. No 0.9%
CVE-2022-23024 HIGH 7.5 f5 big-ip_advanced_firewall_manager On BIG-IP AFM version 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.2, and all versions of 13.1.x, when the IPsec application layer gateway (ALG) logging profile is configured on an IPsec ALG virtual server, undisclosed IPsec traffic can cau 0.9%
CVE-2016-4118 HIGH 7.8 adobe connect Untrusted search path vulnerability in the installer in Adobe Connect Add-In before 11.9.976.291 on Windows allows local users to gain privileges via unspecified vectors. 0.9%
CVE-2026-42903 MED 6.5 microsoft windows_10_1607 Null pointer dereference in Windows Kerberos allows an authorized attacker to deny service over a network. 0.9%
CVE-2025-54917 MED 4.3 microsoft windows_10_1507 Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network. 0.9%
CVE-2023-45284 MED 5.3 golang go On Windows, The IsLocal function does not correctly detect reserved device names in some cases. Reserved names followed by spaces, such as "COM1 ", and reserved names "COM" and "LPT" followed by superscript 1, 2, or 3, are incorrectly reported as local. With f 0.9%
CVE-2023-27871 HIGH 7.5 ibm aspera_faspex IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613. 0.9%
CVE-2022-20918 HIGH 7.5 cisco firepower_services_software_for_asa A vulnerability in the Simple Network Management Protocol (SNMP) access controls for Cisco FirePOWER Software for Adaptive Security Appliance (ASA) FirePOWER module, Cisco Firepower Management Center (FMC) Software, and Cisco Next-Generation Intrusion Preventi 0.9%
CVE-2021-44226 HIGH 7.3 razer synapse Razer Synapse before 3.7.0228.022817 allows privilege escalation because it relies on %PROGRAMDATA%\Razer\Synapse3\Service\bin even if %PROGRAMDATA%\Razer has been created by any unprivileged user before Synapse is installed. The unprivileged user may have pla 0.9%
CVE-2021-24010 HIGH 8.1 fortinet fortisandbox Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated user to obtain unauthorized access to files and data via specifially crafted web requests. 0.9%
CVE-2021-33767 HIGH 8.2 microsoft open_enclave_software_development_kit Open Enclave SDK Elevation of Privilege Vulnerability 0.9%
CVE-2020-0697 HIGH 7.8 microsoft office_365_proplus An elevation of privilege vulnerability exists in Microsoft Office OLicenseHeartbeat task, where an attacker who successfully exploited this vulnerability could run this task as SYSTEM.To exploit the vulnerability, an authenticated attacker would need to place 0.9%