57.811 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.811 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-27747 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2024-38479 | HIGH 7.5 | apache traffic_server Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does n | 0.8% | — |
| CVE-2023-45581 | HIGH 8.8 | fortinet forticlient_enterprise_management_server An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via cra | 0.8% | — |
| CVE-2023-44206 | CRIT 9.1 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979. | 0.8% | — |
| CVE-2022-29120 | MED 6.5 | microsoft windows_server Windows Clustered Shared Volume Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-29102 | MED 5.5 | microsoft windows_server Windows Failover Cluster Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-41015 | MED 6.1 | fortinet fortiweb A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler | 0.8% | — |
| CVE-2021-1463 | MED 6.1 | cisco unified_contact_center_express A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists becaus | 0.8% | — |
| CVE-2021-1409 | MED 6.1 | cisco unified_communications_manager Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management E | 0.8% | — |
| CVE-2021-1408 | MED 6.1 | cisco unified_communications_manager Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management E | 0.8% | — |
| CVE-2021-1407 | MED 6.1 | cisco unified_communications_manager Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management E | 0.8% | — |
| CVE-2021-1380 | MED 6.1 | cisco unified_communications_manager Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management E | 0.8% | — |
| CVE-2020-4406 | MED 5.4 | ibm spectrum_protect_client IBM Spectrum Protect Client 8.1.7.0 through 8.1.9.1 (Linux and Windows), 8.1.9.0 trough 8.1.9.1 (AIX) and IBM Spectrum Protect for Space Management 8.1.7.0 through 8.1.9.1 (Linux), 8.1.9.0 through 8.1.9.1 (AIX) web user interfaces could allow a remote attacker | 0.8% | — |
| CVE-2026-25917 | HIGH 7.2 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 0.8% | — |
| CVE-2025-60722 | MED 6.5 | microsoft onedrive Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-49569 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: unquiesce admin_q before destroy it Kernel will hang on destroy admin_q while we create ctrl failed, such as following calltrace: PID: 23644 TASK: ff2d52b40f439fc0 CPU: 2 | 0.8% | — |
| CVE-2024-38558 | CRIT 10.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix overwriting ct original tuple for ICMPv6 OVS_PACKET_CMD_EXECUTE has 3 main attributes: - OVS_PACKET_ATTR_KEY - Packet metadata in a netlink format. - OVS_PACKET_ATTR_ | 0.8% | — |
| CVE-2022-44696 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44695 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-20922 | MED 5.8 | cisco cyber_vision Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condit | 0.8% | — |
| CVE-2021-38632 | MED 5.7 | microsoft windows_10 Windows BitLocker Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-0281 | MED 5.9 | juniper junos On Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI) receipt of a specific packet from the RPKI cache server may cause routing process daemon (RPD) to crash and restart, creating a Denial of | 0.8% | — |
| CVE-2016-6806 | HIGH 8.8 | apache wicket Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account | 0.8% | — |
| CVE-2015-6374 | MED 4.3 | cisco firepower_extensible_operating_system The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks vi | 0.8% | — |
| CVE-2026-70203 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Media Player allows an unauthorized attacker to execute code over a network. | 0.8% | — |