57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-9896 | HIGH 7.8 | opensuse backports_sle In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable. | 0.8% | — |
| CVE-2018-1214 | HIGH 7.0 | dell emc_supportassist_enterprise Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to | 0.8% | — |
| CVE-2017-12628 | HIGH 7.8 | apache james_server The JMX server embedded in Apache James, also used by the command line client is exposed to a java de-serialization issue, and thus can be used to execute arbitrary commands. As James exposes JMX socket by default only on local-host, this vulnerability can onl | 0.8% | — |
| CVE-2014-1458 | LOW 3.5 | fortinet fortiweb Cross-site scripting (XSS) vulnerability in the web administration interface in FortiGuard FortiWeb 5.0.3 and earlier allows remote authenticated administrators to inject arbitrary web script or HTML via unspecified vectors. | 0.8% | — |
| CVE-2013-5634 | MED 4.3 | linux linux_kernel arch/arm/kvm/arm.c in the Linux kernel before 3.10 on the ARM platform, when KVM is used, allows host OS users to cause a denial of service (NULL pointer dereference, OOPS, and host OS crash) or possibly have unspecified other impact by omitting vCPU initializ | 0.8% | — |
| CVE-2026-47645 | HIGH 8.8 | microsoft 365_copilot Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-27483 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2024-47604 | HIGH 8.2 | microsoft nugetgallery NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary HTML or Javascript code in a victim's browser. | 0.8% | — |
| CVE-2024-27784 | HIGH 8.8 | fortinet fortiaiops Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an authenticated, remote attacker to retrieve sensitive information from the API endpoint or log files. | 0.8% | — |
| CVE-2023-36418 | HIGH 7.8 | microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2026-21228 | HIGH 8.1 | microsoft azure_local Improper certificate validation in Azure Local allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-29847 | HIGH 7.5 | apache linkis A vulnerability in Apache Linkis. Problem Description When using the JDBC engine and da When using the JDBC engine and data source functionality, if the URL parameter configured on the frontend has undergone multiple rounds of URL encoding, it may bypass the | 0.8% | — |
| CVE-2025-21193 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0.8% | — |
| CVE-2024-46737 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet-tcp: fix kernel crash if commands allocation fails If the commands allocation fails in nvmet_tcp_alloc_cmds() the kernel crashes in nvmet_tcp_release_queue_work() because of a NULL poi | 0.8% | — |
| CVE-2024-40980 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drop_monitor: replace spin_lock by raw_spin_lock trace_drop_common() is called with preemption disabled, and it acquires a spin_lock. This is problematic for RT kernels because spin_locks ar | 0.8% | — |
| CVE-2024-21309 | HIGH 7.8 | microsoft windows_11_21h2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-20682 | HIGH 7.8 | microsoft windows_10_1507 Windows Cryptographic Services Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-47703 | MED 5.3 | ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Forc | 0.8% | — |
| CVE-2023-28365 | CRIT 9.1 | ui unifi_network_application A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. | 0.8% | — |
| CVE-2020-27726 | MED 6.1 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG- | 0.8% | — |
| CVE-2020-27719 | MED 6.1 | f5 big-ip_access_policy_manager On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. | 0.8% | — |
| CVE-2020-26077 | MED 4.3 | cisco iot_field_network_director A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to imp | 0.8% | — |
| CVE-2015-0674 | MED 6.1 | cisco cloud_web_security Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | 0.8% | — |
| CVE-2026-56191 | CRIT 10.0 | microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. | 0.8% | — |
| CVE-2026-47655 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 0.8% | — |