57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2009-4914 | HIGH 7.8 | cisco asa_5580 Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879 | 0.7% | — |
| CVE-2026-24012 | HIGH 7.5 | apache iotdb Uncontrolled Resource Consumption vulnerability in Apache IoTDB. Some interface fails to impose reasonable limits on the time span and aggregation interval of the query. An attacker can construct a request with extreme parameters (e.g., a very large time ran | 0.7% | — |
| CVE-2026-53917 | HIGH 7.5 | apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker. An authenticated user can cause a broker DoS by sending a crafted OpenWire Message with a large encoded size val | 0.7% | — |
| CVE-2026-53916 | HIGH 7.5 | apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. An unauthenticated client that opens a STOMP NIO connection can send header bytes that never terminate which makes the broker buffer the | 0.7% | — |
| CVE-2026-50734 | HIGH 7.5 | apache activemq Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All. An unauthenticated network attacker can cause a broker DoS by sending a crafted WireFormatInfo frame with a malicious large size value. | 0.7% | — |
| CVE-2026-42588 | HIGH 8.1 | apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console | 0.7% | — |
| CVE-2024-50095 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/mad: Improve handling of timed out WRs of mad agent Current timeout handler of mad agent acquires/releases mad_agent_priv lock for every timed out WRs. This causes heavy locking content | 0.7% | — |
| CVE-2024-20478 | MED 6.5 | cisco application_policy_infrastructure_controller A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges | 0.7% | — |
| CVE-2021-46955 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix stack OOB read while fragmenting IPv4 packets running openvswitch on kernels built with KASAN, it's possible to see the following splat while testing fragmentation of IPv4 p | 0.7% | — |
| CVE-2023-20231 | HIGH 8.8 | cisco ios_xe A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulner | 0.7% | — |
| CVE-2023-27730 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_lvlhsh_find at src/njs_lvlhsh.c. | 0.7% | — |
| CVE-2023-27728 | HIGH 7.5 | f5 njs Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c. | 0.7% | — |
| CVE-2023-21718 | HIGH 7.8 | microsoft sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-33876 | MED 5.4 | fortinet fortiadc Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and below allows an authenticated attacker to retrieve files with specific extension from the underlying Linux syste | 0.7% | — |
| CVE-2022-21962 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21961 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21960 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21959 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21958 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-21892 | MED 6.8 | microsoft windows_10 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-34712 | MED 5.4 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct cypher query language injection attacks on an affected system. This vulnerability is due to insufficient input valid | 0.7% | — |
| CVE-2021-1642 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-9498 | MED 6.7 | apache guacamole Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possib | 0.7% | — |
| CVE-2017-0302 | MED 5.3 | f5 big-ip_access_policy_manager In F5 BIG-IP APM 12.0.0 through 12.1.2 and 13.0.0, an authenticated user with an established access session to the BIG-IP APM system may be able to cause a traffic disruption if the length of the requested URL is less than 16 characters. | 0.7% | — |
| CVE-2026-31987 | HIGH 7.5 | apache airflow JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that contains fix. Users are recommended to upgrade to version 3.2.0, which fixes this issue. | 0.7% | — |