57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2007-6192 | MED 4.3 | citrix netscaler The web management interface in Citrix NetScaler 8.0 build 47.8 uses weak encryption (XOR of unpadded data) to store credentials within a cookie, which makes it easier for remote attackers to obtain cleartext credentials when a cookie is captured via a known-p | 0.7% | — |
| CVE-2025-20152 | HIGH 8.6 | cisco identity_services_engine A vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handli | 0.7% | — |
| CVE-2025-26413 | HIGH 7.5 | apache kvrocks Improper Input Validation vulnerability in Apache Kvrocks. The SETRANGE command didn't check if the `offset` input is a positive integer and use it as an index of a string. So it will cause the server to crash due to its index is out of range. This issue aff | 0.7% | — |
| CVE-2025-24067 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Microsoft Streaming Service allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-24066 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-21341 | MED 6.6 | microsoft windows_10_1507 Windows Digital Media Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35351 | MED 6.6 | microsoft windows_server_2008 Windows Active Directory Certificate Services (AD CS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35346 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35345 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-35344 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2020-29371 | LOW 3.3 | linux linux_kernel An issue was discovered in romfs_dev_read in fs/romfs/storage.c in the Linux kernel before 5.8.4. Uninitialized memory leaks to userspace, aka CID-bcf85fcedfdd. | 0.7% | — |
| CVE-2019-6696 | MED 6.1 | fortinet fortios An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage. | 0.7% | — |
| CVE-2019-16154 | MED 6.1 | fortinet fortiauthenticator An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page. | 0.7% | — |
| CVE-2019-1764 | HIGH 8.1 | cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. The vulnerability is due t | 0.7% | — |
| CVE-2019-3701 | MED 4.4 | canonical ubuntu_linux An issue was discovered in can_can_gw_rcv in net/can/gw.c in the Linux kernel through 4.19.13. The CAN frame modification rules allow bitwise logical operations that can be also applied to the can_dlc field. The privileged user "root" with CAP_NET_ADMIN can cr | 0.7% | — |
| CVE-2009-0028 | LOW 2.1 | linux linux_kernel The clone system call in the Linux kernel 2.6.28 and earlier allows local users to send arbitrary signals to a parent process from an unprivileged child process by launching an additional child process with the CLONE_PARENT flag, and then letting this new proc | 0.7% | — |
| CVE-2026-49297 | HIGH 8.1 | apache apache-airflow-providers-google Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GCSTimeSpanFileTransformOperator` joined GCS object names returned by the bucket listing API directly to a destination filesystem path without normalisation or containment check. A user with w | 0.7% | — |
| CVE-2025-47158 | CRIT 9.0 | microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-49052 | HIGH 8.2 | microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-26954 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() If ->NameOffset of smb2_create_req is smaller than Buffer offset of smb2_create_req, slab-out-of-bounds read can happen from smb2_op | 0.7% | — |
| CVE-2024-29981 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.7% | — |
| CVE-2023-38734 | MED 6.6 | ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481. | 0.7% | — |
| CVE-2022-23831 | HIGH 7.5 | amd amd_uprof Insufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential Windows kernel crash resulting in denial of service. | 0.7% | — |
| CVE-2022-22213 | MED 5.9 | juniper junos A vulnerability in Handling of Undefined Values in the routing protocol daemon (RPD) process of Juniper Networks Junos OS and Junos OS Evolved may allow an unauthenticated network-based attacker to crash the RPD process by sending a specific BGP update while t | 0.7% | — |
| CVE-2020-5947 | MED 4.3 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1 and 15.1.0-15.1.1, on specific BIG-IP platforms, attackers may be able to obtain TCP sequence numbers from the BIG-IP system that can be reused in future connections with the same source and destination port and IP numbers. Only the | 0.7% | — |