57.725 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.725 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50415 | MED 5.3 | microsoft windows_10_1809 Exposure of sensitive information to an unauthorized actor in Windows Media allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-20436 | HIGH 8.6 | cisco ios_xe A vulnerability in the HTTP Server feature of Cisco IOS XE Software when the Telephony Service feature is enabled could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due t | 0.9% | — |
| CVE-2024-44946 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: kcm: Serialise kcm_sendmsg() for the same socket. syzkaller reported UAF in kcm_release(). [0] The scenario is 1. Thread A builds a skb with MSG_MORE and sets kcm->seq_skb. 2. Thread | 0.9% | — |
| CVE-2023-42501 | MED 4.3 | apache superset Unnecessary read permissions within the Gamma role would allow authenticated users to read configured CSS templates and annotations. This issue affects Apache Superset: before 2.1.2. Users should upgrade to version or above 2.1.2 and run `superset init` to rec | 0.9% | — |
| CVE-2023-44156 | HIGH 7.5 | acronis cyber_protect Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.9% | — |
| CVE-2023-24069 | LOW 3.3 | signal signal-desktop Signal Desktop before 6.2.0 on Windows, Linux, and macOS allows an attacker to obtain potentially sensitive attachments sent in messages from the attachments.noindex directory. Cached attachments are not effectively cleared. In some cases, even after a self-in | 0.9% | — |
| CVE-2015-10011 | MED 4.6 | cisco openresolve A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an unknown part of the file resolverapi/endpoints.py. The manipulation leads to improper output neutralization for logs. The identifier of the patch is 9eba6ba5abd89d | 0.9% | — |
| CVE-2021-42277 | MED 5.5 | microsoft visual_studio Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2019-1609 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to c | 0.9% | — |
| CVE-2016-4810 | HIGH 7.5 | citrix xenapp Citrix Studio before 7.6.1000, Citrix XenDesktop 7.x before 7.6 LTSR Cumulative Update 1 (CU1), and Citrix XenApp 7.5 and 7.6 allow attackers to set Access Policy rules on the XenDesktop Delivery Controller via unspecified vectors. | 0.9% | — |
| CVE-2026-69683 | MED 6.5 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-20165 | HIGH 7.5 | cisco broadworks_network_server A vulnerability in the SIP processing subsystem of Cisco BroadWorks could allow an unauthenticated, remote attacker to halt the processing of incoming SIP requests, resulting in a denial of service (DoS) condition. This vulnerability is due to improper memo | 0.9% | — |
| CVE-2024-38261 | HIGH 7.8 | microsoft windows_server_2008 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38066 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32k Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2023-37139 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a stack overflow vulnerability via the function Js::ScopeSlots::IsDebuggerScopeSlotArray(). | 0.9% | — |
| CVE-2022-34882 | CRIT 9.0 | hitachi raid_manager_storage_replication_adapter Information Exposure Through an Error Message vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users to gain sensitive information. This issue affects: Hitachi RAID Manager Storage Replication Adapter 02.01.04 versi | 0.9% | — |
| CVE-2021-3061 | MED 6.4 | paloaltonetworks pan-os An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions e | 0.9% | — |
| CVE-2021-31970 | MED 5.5 | microsoft windows_10 Windows TCP/IP Driver Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2020-5920 | MED 4.3 | f5 big-ip_advanced_firewall_manager In versions 15.0.0-15.1.0.5, 14.1.0-14.1.2.7, 13.1.0-13.1.3.4, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, a vulnerability in the BIG-IP AFM Configuration utility may allow any authenticated BIG-IP user to perform a read-only blind SQL injection attack. | 0.9% | — |
| CVE-2019-16157 | MED 6.5 | fortinet fortiweb An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being logged via diagnose debug commands. | 0.9% | — |
| CVE-2019-6662 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request. Users with access to the log files would be able to view that data. | 0.9% | — |
| CVE-2019-14823 | HIGH 7.4 | jss_cryptomanager_project jss_cryptomanager A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the ch | 0.9% | — |
| CVE-2011-3298 | HIGH 7.9 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices, and the ASA Services module in Cisco Catalyst 6500 series devices, with software 7.0 before 7.0(8.13), 7.1 and 7.2 before 7.2(5.3), 8.0 before 8.0(5.24), 8.1 before 8.1(2.50), 8.2 before 8.2(5), 8.3 | 0.9% | — |
| CVE-2010-2841 | MED 6.8 | cisco wireless_lan_controller_software Unspecified vulnerability in Cisco Wireless LAN Controller (WLC) software 4.2 before 4.2.209.0; 4.2M before 4.2.207.54M; 5.0, 5.1, and 6.0 before 6.0.196.0; and 5.2 before 5.2.193.11 allows remote authenticated users to cause a denial of service (device reload | 0.9% | — |
| CVE-2006-5701 | MED 4.9 | linux linux_kernel Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem. | 0.9% | — |