57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-10727 | MED 5.5 | apache artemis A flaw was found in ActiveMQ Artemis management API from version 2.7.0 up until 2.12.0, where a user inadvertently stores passwords in plaintext in the Artemis shadow file (etc/artemis-users.properties file) when executing the `resetUsers` operation. A local a | 0.7% | — |
| CVE-2019-6688 | MED 4.3 | f5 big-ip_access_policy_manager On BIG-IP versions 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5 and BIG-IQ versions 6.0.0-6.1.0 and 5.2.0-5.4.0, a user is able to obtain the secret that was being used to encrypt a BIG-IP UCS backup file w | 0.7% | — |
| CVE-2014-0219 | MED 5.5 | apache karaf Apache Karaf before 4.0.10 enables a shutdown port on the loopback interface, which allows local users to cause a denial of service (shutdown) by sending a shutdown command to all listening high ports. | 0.7% | — |
| CVE-2015-6307 | MED 6.1 | cisco firepower Cisco FirePOWER (formerly Sourcefire) 7000 and 8000 devices with software 5.4.0.1 allow remote attackers to cause a denial of service (inspection-engine outage) via crafted packets, aka Bug ID CSCuu10871. | 0.7% | — |
| CVE-1999-0138 | HIGH 7.2 | apple a_ux The suidperl and sperl program do not give up root privileges when changing UIDs back to the original users, allowing root access. | 0.7% | — |
| CVE-2026-69858 | HIGH 8.1 | microsoft windows_server_2022 Use after free in Windows DNS allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-70324 | HIGH 8.8 | microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-53217 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent NULL dereference in nfsd4_process_cb_update() @ses is initialized to NULL. If __nfsd4_find_backchannel() finds no available backchannel session, setup_callback_client() will tr | 0.7% | — |
| CVE-2024-38078 | HIGH 7.5 | microsoft windows_11_21h2 Xbox Wireless Adapter Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-26689 | HIGH 8.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ceph: prevent use-after-free in encode_cap_msg() In fs/ceph/caps.c, in encode_cap_msg(), "use after free" error was caught by KASAN at this line - 'ceph_buffer_get(arg->xattr_buf);'. This im | 0.7% | — |
| CVE-2023-21738 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-20795 | MED 5.8 | cisco adaptive_security_appliance A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resul | 0.7% | — |
| CVE-2018-1353 | MED 4.3 | fortinet fortimanager An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom. | 0.7% | — |
| CVE-2015-7363 | MED 5.4 | fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrato | 0.7% | — |
| CVE-2026-68476 | CRIT 9.8 | In the Linux kernel, the following vulnerability has been resolved: ipvs: reload ip header after head reallocation __ip_vs_get_out_rt() calls skb_ensure_writable() which may reallocate skb->head. | 0.7% | — |
| CVE-2026-70468 | HIGH 8.1 | fortinet fortimanager A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7. | 0.7% | — |
| CVE-2026-59113 | HIGH 8.8 | microsoft visual_studio_code Missing authorization in Visual Studio Code allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-69219 | HIGH 8.8 | apache airflow_providers_http A user with access to the DB could craft a database entry that would result in executing code on Triggerer - which gives anyone who have access to DB the same permissions as Dag Author. Since direct DB access is not usual and recommended for Airflow, the likel | 0.7% | — |
| CVE-2026-20837 | HIGH 7.8 | microsoft windows_10_1809 Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-55674 | MED 6.5 | apache superset A bypass of the DISALLOWED_SQL_FUNCTIONS security feature in Apache Superset allows for the execution of blocked SQL functions. An attacker can use a special inline block to circumvent the denylist. This allows a user with SQL Lab access to execute functions t | 0.7% | — |
| CVE-2025-21206 | HIGH 7.3 | microsoft visual_studio_2017 Visual Studio Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38247 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38046 | HIGH 7.8 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-23662 | MED 5.3 | fortinet fortios An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP request | 0.7% | — |
| CVE-2024-22371 | LOW 2.9 | apache camel Exposure of sensitive data by by crafting a malicious EventFactory and providing a custom ExchangeCreatedEvent that exposes sensitive data. Vulnerability in Apache Camel.This issue affects Apache Camel: from 3.21.X through 3.21.3, from 3.22.X through 3.22.0, f | 0.7% | — |