57.638 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.638 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-78523 | MED 5.9 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2025-21756 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vsock: Keep the binding until socket destruction Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during connect(). | 0.9% | — |
| CVE-2024-26016 | MED 4.3 | apache superset A low privilege authenticated user could import an existing dashboard or chart that they do not have access to and then modify its metadata, thereby gaining ownership of the object. However, it's important to note that access to the analytical data of these ch | 0.9% | — |
| CVE-2023-28301 | LOW 3.7 | microsoft edge Microsoft Edge (Chromium-based) Tampering Vulnerability | 0.9% | — |
| CVE-2023-21766 | MED 4.7 | microsoft windows_10 Windows Overlay Filter Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-38869 | CRIT 9.8 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. | 0.9% | — |
| CVE-2021-40126 | MED 4.3 | cisco umbrella A vulnerability in the web-based dashboard of Cisco Umbrella could allow an authenticated, remote attacker to perform an email enumeration attack against the Umbrella infrastructure. This vulnerability is due to an overly descriptive error message on the dashb | 0.9% | — |
| CVE-2021-31350 | HIGH 7.5 | juniper junos An Improper Privilege Management vulnerability in the gRPC framework, used by the Juniper Extension Toolkit (JET) API on Juniper Networks Junos OS and Junos OS Evolved, allows a network-based, low-privileged authenticated attacker to perform operations as root | 0.9% | — |
| CVE-2021-34702 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to improper enforcement of administrator privilege levels for | 0.9% | — |
| CVE-2021-34765 | MED 4.3 | cisco nexus_insights A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote attacker to view and download files related to the web application. The attacker requires valid device credentials. This vulnerability exists because proper role-based | 0.9% | — |
| CVE-2021-1562 | MED 4.3 | cisco broadworks_application_server A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow an authenticated, remote attacker to access sensitive information on an affected system. This vulnerability is due to improper input validation and authorization of | 0.9% | — |
| CVE-2021-26898 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2018-15310 | MED 4.3 | f5 big-ip_access_policy_manager A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages. | 0.9% | — |
| CVE-2014-3379 | MED 6.1 | cisco ios_xr Cisco IOS XR 5.1 and earlier on Network Convergence System 6000 devices allows remote attackers to cause a denial of service (NPU and card hang or reload) via a malformed MPLS packet, aka Bug ID CSCuq10466. | 0.9% | — |
| CVE-2002-1380 | LOW 2.1 | linux linux_kernel Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ parameter to access non-readable memory pages through the /proc/pid/mem interface. | 0.9% | — |
| CVE-2026-40473 | HIGH 8.8 | apache camel The camel-mina component's MinaConverter.toObjectInput(IoBuffer) type converter wraps an IoBuffer in a java.io.ObjectInputStream without applying any ObjectInputFilter or class-loading restrictions. When a Camel route uses camel-mina as a TCP or UDP consumer a | 0.9% | — |
| CVE-2025-26627 | HIGH 7.0 | microsoft azure_arc Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2023-42786 | MED 6.5 | fortinet fortios A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request. | 0.9% | — |
| CVE-2024-41081 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ila: block BH in ila_output() As explained in commit 1378817486d6 ("tipc: block BH before using dst_cache"), net/core/dst_cache.c helpers need to be called with BH disabled. ila_output() is | 0.9% | — |
| CVE-2023-36561 | HIGH 7.3 | microsoft azure_devops_server Azure DevOps Server Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-44249 | MED 4.3 | fortinet fortianalyzer An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privileges to read sensitive information via | 0.9% | — |
| CVE-2023-35358 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-35357 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-37386 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.2.53575. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2022-37383 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |