57.962 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.962 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2005-3808 | MED 4.9 | linux linux_kernel Integer overflow in the invalidate_inode_pages2_range function in mm/truncate.c in Linux kernel 2.6.11 to 2.6.14 allows local users to cause a denial of service (hang) via 64-bit mmap calls that are not properly handled on a 32-bit system. | 0.8% | — |
| CVE-2004-0228 | HIGH 7.2 | linux linux_kernel Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges. | 0.8% | — |
| CVE-2026-30898 | HIGH 8.8 | apache airflow An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own | 0.8% | — |
| CVE-2025-59249 | HIGH 8.8 | microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-48784 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI a | 0.8% | — |
| CVE-2023-5257 | LOW 3.5 | whitehsbg jndiexploit A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFileRequest of the file src/main/java/com/feihong/ldap/HTTPServer.java. The manipulation leads to path traversal. | 0.8% | — |
| CVE-2023-29353 | MED 5.5 | microsoft sysinternals Sysinternals Process Monitor for Windows Denial of Service Vulnerability | 0.8% | — |
| CVE-2021-22047 | MED 5.3 | vmware spring_data_rest In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c | 0.8% | — |
| CVE-2021-27195 | MED 5.9 | netop vision_pro Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | 0.8% | — |
| CVE-2020-1273 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0.8% | — |
| CVE-2020-1162 | HIGH 7.8 | microsoft windows_10 An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vul | 0.8% | — |
| CVE-2015-3006 | MED 6.5 | juniper junos On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after t | 0.8% | — |
| CVE-2016-8475 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the HTC input driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: An | 0.8% | — |
| CVE-2016-8474 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr | 0.8% | — |
| CVE-2016-8473 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr | 0.8% | — |
| CVE-2016-8469 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Andro | 0.8% | — |
| CVE-2000-0227 | LOW 2.1 | linux linux_kernel The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets. | 0.8% | — |
| CVE-2020-12819 | MED 5.4 | fortinet fortios A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a | 0.8% | — |
| CVE-2022-30162 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2019-6695 | CRIT 9.8 | fortinet fortimanager Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods. | 0.8% | — |
| CVE-2016-1090 | HIGH 7.8 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege | 0.8% | — |
| CVE-2016-1087 | HIGH 7.8 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege | 0.8% | — |
| CVE-2026-65905 | CRIT 9.8 | apache tomcat Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that | 0.8% | — |
| CVE-2026-40375 | MED 6.5 | microsoft dynamics_365_business_central_2024 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-25001 | MED 4.3 | microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |