IT
57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.620 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-0430 HIGH 7.8 google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compr 0.9%
CVE-2010-4249 MED 4.9 fedoraproject fedora The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted u 0.9%
CVE-2026-69739 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-69626 MED 6.5 microsoft 365_apps Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2024-20694 MED 5.5 microsoft windows_10_1607 Windows CoreMessaging Information Disclosure Vulnerability 0.9%
CVE-2022-20917 MED 4.3 cisco jabber A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulne 0.9%
CVE-2023-21564 HIGH 7.1 microsoft azure_devops_server Azure DevOps Server Cross-Site Scripting Vulnerability 0.9%
CVE-2021-43081 MED 6.1 fortinet fortios An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and below, 6.0.14 to 6.0.0. and in FortiProxy version 7.0.1 and below, 2.0.7 to 2.0.0 web filter override form may 0.9%
CVE-2021-36081 HIGH 7.8 tesseract-ocr tesseract_ocr Tesseract OCR 5.0.0-alpha-20201231 has a one_ell_conflict use-after-free during a strpbrk call. 0.9%
CVE-2021-25248 MED 5.5 trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple 0.9%
CVE-2020-27724 MED 6.5 f5 big-ip_access_policy_manager In BIG-IP APM versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, on systems running more than one TMM instance, authenticated VPN users may consume excessive resources by sending sp 0.9%
CVE-2020-1676 HIGH 7.2 juniper mist_cloud_ui When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security cont 0.9%
CVE-2008-1113 HIGH 7.8 vocera_communications vocera_communications_badge Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. 0.9%
CVE-2006-1095 HIGH 7.2 apache mod_python Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie. 0.9%
CVE-2026-65681 HIGH 7.5 microsoft windows_10_1607 Null pointer dereference in Windows iSCSI Target Service allows an unauthorized attacker to deny service over a network. 0.9%
CVE-2026-40859 HIGH 8.1 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any Object 0.9%
CVE-2026-42780 MED 4.9 f5 big-ip_ssl_orchestrator A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software versions which have reached End of Technical Support (EoTS) a 0.9%
CVE-2026-24464 MED 6.8 f5 big-ip_access_policy_manager When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files.  Note: Software versi 0.9%
CVE-2026-25173 HIGH 8.0 microsoft windows_10_1607 Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-23907 MED 5.3 apache pdfbox This issue affects the ExtractEmbeddedFiles example in Apache PDFBox: from 2.0.24 through 2.0.35, from 3.0.0 through 3.0.6. The ExtractEmbeddedFiles example contains a path traversal vulnerability (CWE-22) because the filename that is obtained from PDComp 0.9%
CVE-2024-44947 MED 5.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fuse: Initialize beyond-EOF page contents before setting uptodate fuse_notify_store(), unlike fuse_do_readpage(), does not enable page zeroing (because it can be used to change partial page 0.9%
CVE-2022-20926 MED 6.3 cisco secure_firewall_management_center A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient 0.9%
CVE-2021-35248 MED 6.8 solarwinds orion_platform It has been reported that any Orion user, e.g. guest accounts can query the Orion.UserSettings entity and enumerate users and their basic settings. 0.9%
CVE-2021-29691 HIGH 7.5 ibm security_identity_manager IBM Security Identity Manager 7.0.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 20025 0.9%
CVE-2020-5020 MED 6.1 ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click act 0.9%