57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-37142 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::EntryPointInfo::HasInlinees(). | 0.8% | — |
| CVE-2023-37141 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). | 0.8% | — |
| CVE-2023-37140 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). | 0.8% | — |
| CVE-2022-38652 | CRIT 9.9 | vmware hyperic_agent A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with | 0.8% | — |
| CVE-2020-2017 | HIGH 8.8 | paloaltonetworks pan-os A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to PAN-OS and Panorama Web Interfaces could execute arbitrary J | 0.8% | — |
| CVE-2020-1637 | HIGH 7.2 | juniper junos A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured in the Infranet Cont | 0.8% | — |
| CVE-2019-19150 | MED 4.9 | f5 big-ip_access_policy_manager On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server with debug logging enabled. | 0.8% | — |
| CVE-2018-18517 | MED 4.8 | citrix netscaler_gateway_firmware Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. | 0.8% | — |
| CVE-2005-2800 | LOW 2.1 | linux linux_kernel Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not | 0.8% | — |
| CVE-2026-46454 | CRIT 9.8 | apache camel Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies | 0.8% | — |
| CVE-2026-41105 | HIGH 8.1 | microsoft azure_monitor_action_group_notification_system Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-32211 | CRIT 9.1 | microsoft azure_web_apps Missing authentication for critical function in Azure MCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2024-38169 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-35260 | HIGH 8.0 | microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | 0.8% | — |
| CVE-2023-33305 | MED 4.9 | fortinet fortios A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2. | 0.8% | — |
| CVE-2021-38939 | MED 5.3 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 stores potentially sensitive information in log files that could be read by an user with access to creating domains. IBM X-Force ID: 211037. | 0.8% | — |
| CVE-2022-22169 | MED 5.9 | juniper junos An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter gracef | 0.8% | — |
| CVE-2021-41345 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-0129 | MED 5.7 | bluez bluez Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. | 0.8% | — |
| CVE-2020-1271 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Backup Service Elevation of Privi | 0.8% | — |
| CVE-2020-1222 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Microsoft Store Runtime Elevation of Privilege Vu | 0.8% | — |
| CVE-2019-1478 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists when Windows improperly handles COM object creation, aka 'Windows COM Server Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-1673 | MED 5.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to in | 0.8% | — |
| CVE-2025-29826 | HIGH 7.3 | microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-49092 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.8% | — |