57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-47706 | MED 6.6 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow an authenticated user to upload files of a dangerous file type. IBM X-Force ID: 271341. | 0.8% | — |
| CVE-2021-3048 | MED 5.9 | paloaltonetworks pan-os Certain invalid URL entries contained in an External Dynamic List (EDL) cause the Device Server daemon (devsrvr) to stop responding. This condition causes subsequent commits on the firewall to fail and prevents administrators from performing commits and config | 0.8% | — |
| CVE-2020-3311 | MED 6.1 | cisco secure_firewall_management_center A vulnerability in the web interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of HTTP request parameter | 0.8% | — |
| CVE-2020-3178 | MED 6.1 | cisco content_security_management_appliance Multiple vulnerabilities in the web-based GUI of Cisco AsyncOS Software for Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. The vulnerabilities are due to improper in | 0.8% | — |
| CVE-2017-6543 | HIGH 7.3 | tenable appliance Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to subseque | 0.8% | — |
| CVE-2026-41094 | HIGH 8.8 | microsoft data_formulator Improper control of generation of code ('code injection') in Microsoft Data Formulator allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-30389 | HIGH 8.7 | microsoft azure_ai_bot_service Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-21344 | HIGH 7.8 | microsoft sharepoint_server Microsoft SharePoint Server Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2020-26062 | MED 5.3 | cisco unified_computing_system A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated, remote attacker to enumerate valid usernames within the vulnerable application. The vulnerability is due to differences in authentication responses sent back from t | 0.8% | — |
| CVE-2022-21978 | HIGH 8.2 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-24493 | MED 5.5 | microsoft windows_10 Microsoft Local Security Authority (LSA) Server Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-31371 | MED 5.3 | juniper junos Juniper Networks Junos OS uses the 128.0.0.0/2 subnet for internal communications between the RE and PFEs. It was discovered that packets utilizing these IP addresses may egress an QFX5000 Series switch, leaking configuration information such as heartbeats, ke | 0.8% | — |
| CVE-2020-27727 | MED 4.9 | f5 big-ip_access_policy_manager On BIG-IP version 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, and 13.1.0-13.1.3.4, when an authenticated administrative user installs RPMs using the iAppsLX REST installer, the BIG-IP system does not sufficiently validate user input, allowing the user rea | 0.8% | — |
| CVE-2019-1415 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins | 0.8% | — |
| CVE-2017-4917 | CRIT 9.8 | vmware vsphere_data_protection VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x locally stores vCenter Server credentials using reversible encryption. This issue may allow plaintext credentials to be obtained. | 0.8% | — |
| CVE-2026-9135 | CRIT 9.9 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false secur | 0.8% | — |
| CVE-2026-24307 | CRIT 9.3 | microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-12763 | MED 6.8 | pgadmin pgadmin_4 pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused by the use of shell=True during backup and restore operations, enabling attackers to execute arbitrary system commands by providing speciall | 0.8% | — |
| CVE-2024-30065 | MED 5.5 | microsoft windows_10_1507 Windows Themes Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-20693 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-33146 | HIGH 7.8 | microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-30268 | CRIT 9.8 | cltphp cltphp CLTPHP <=6.0 is vulnerable to Improper Input Validation. | 0.8% | — |
| CVE-2022-20786 | MED 5.4 | cisco unified_communications_manager_im_and_presence_service A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerabili | 0.8% | — |
| CVE-2018-5803 | MED 5.5 | debian debian_linux In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash. | 0.8% | — |
| CVE-2018-0215 | MED 6.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnera | 0.8% | — |