IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-47984 MED 6.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 243163. 0.7%
CVE-2022-2622 MED 6.5 fedoraproject fedora Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file. 0.7%
CVE-2022-30535 MED 6.5 f5 nginx_ingress_controller In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are no 0.7%
CVE-2019-19332 MED 6.1 linux linux_kernel An out-of-bounds memory write issue was found in the Linux Kernel, version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by the KVM hypervisor. A user or proc 0.7%
CVE-2016-2067 HIGH 7.8 google android drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows atta 0.7%
CVE-2014-1210 MED 5.8 vmware vsphere_client VMware vSphere Client 5.0 before Update 3 and 5.1 before Update 2 does not properly validate X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. 0.7%
CVE-2026-62910 HIGH 7.2 microsoft exchange_server Improper control of resource identifiers ('resource injection') in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.7%
CVE-2026-53421 CRIT 9.8 apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code execution through the connector subsystem by relying on scripted connectors' (REST and SQL) capability to run Gro 0.7%
CVE-2024-24778 MED 6.5 apache streampipes Improper privilege management in a REST interface allowed registered users to access unauthorized resources if the resource ID was know. This issue affects Apache StreamPipes: through 0.95.1. Users are recommended to upgrade to version 0.97.0 which fixe 0.7%
CVE-2023-28222 HIGH 7.1 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.7%
CVE-2023-20081 MED 6.8 cisco adaptive_security_appliance_software A vulnerability in the IPv6 DHCP (DHCPv6) client module of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a 0.7%
CVE-2022-20952 MED 5.3 cisco asyncos A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attacker to bypass a configured rule, thereby allowing traffic onto a 0.7%
CVE-2023-20057 NONE 0.0 cisco asyncos A vulnerability in the URL filtering mechanism of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. This vulnerability is due to improp 0.7%
CVE-2022-21912 HIGH 7.8 microsoft windows_10 DirectX Graphics Kernel Remote Code Execution Vulnerability 0.7%
CVE-2022-21875 HIGH 7.0 microsoft windows_10 Windows Storage Elevation of Privilege Vulnerability 0.7%
CVE-2022-21873 HIGH 7.0 microsoft windows_10 Tile Data Repository Elevation of Privilege Vulnerability 0.7%
CVE-2022-21872 HIGH 7.0 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.7%
CVE-2022-21870 HIGH 7.0 microsoft windows_10 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability 0.7%
CVE-2019-7222 MED 5.5 canonical ubuntu_linux The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak. 0.7%
CVE-2018-0408 MED 5.4 cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management 0.7%
CVE-2018-0407 MED 5.4 cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series (Sx300) Managed Switches could allow an authenticated, remote attacker to conduct a persistent cross-site scripting (XSS) attack against a user of the web-based management 0.7%
CVE-2014-7991 MED 4.3 cisco unified_communications_manager The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices 0.7%
CVE-2013-0346 LOW 2.1 apache tomcat Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensi 0.7%
CVE-2026-63041 HIGH 8.8 apache apisix Reliance on Untrusted Inputs in a Security Decision vulnerability in Apache APISIX. This vulnerability allows an attacker to escalate privilege or perform an authorization bypass by sending certain values that the attach-consumer-label plugin does not sanitis 0.7%
CVE-2026-45860 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections ar 0.7%