57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-1552 | HIGH 7.5 | debian debian_linux Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior.*Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. | 0.7% | — |
| CVE-2023-34058 | HIGH 7.1 | debian debian_linux VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target vi | 0.7% | — |
| CVE-2023-38041 | HIGH 7.0 | ivanti secure_access_client A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | 0.7% | — |
| CVE-2020-36516 | MED 5.9 | linux linux_kernel An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP session or terminate that session. | 0.7% | — |
| CVE-2017-7340 | MED 6.1 | fortinet fortiportal A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality. | 0.7% | — |
| CVE-2017-7518 | MED 5.5 | canonical ubuntu_linux A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process insi | 0.7% | — |
| CVE-2016-8414 | MED 4.7 | google android An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising | 0.7% | — |
| CVE-2016-8658 | MED 6.1 | linux linux_kernel Stack-based buffer overflow in the brcmf_cfg80211_start_ap function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.7.5 allows local users to cause a denial of service (system crash) or possibly have unspecified othe | 0.7% | — |
| CVE-2026-40376 | HIGH 7.5 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-23571 | MED 6.8 | teamviewer digital_employee_experience A command injection vulnerability was discovered in TeamViewer DEX (former 1E DEX), specifically within the 1E-Nomad-RunPkgStatusRequest instruction. Improper input validation allows authenticated attackers with actioner privilege to run elevated arbitrary com | 0.7% | — |
| CVE-2025-55248 | MED 4.8 | microsoft .net Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-47167 | HIGH 8.4 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2024-20331 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the session authentication functionality of the Remote Access SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to prevent us | 0.7% | — |
| CVE-2024-20686 | HIGH 7.8 | microsoft windows_server_2022_23h2 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-35343 | HIGH 7.8 | microsoft windows_10_1809 Windows Geolocation Service Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28226 | MED 5.3 | microsoft windows_10_1507 Windows Enroll Engine Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2022-42439 | MED 6.8 | ibm app_connect_enterprise IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 23 | 0.7% | — |
| CVE-2022-21973 | MED 5.5 | microsoft windows_7 Windows Media Center Update Denial of Service Vulnerability | 0.7% | — |
| CVE-2020-5018 | HIGH 7.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.6 may include sensitive information in its URLs increasing the risk of such information being caputured by an attacker. IBM X-Force ID: 193654. | 0.7% | — |
| CVE-2019-16002 | MED 6.5 | cisco sd-wan_firmware A vulnerability in the vManage web-based UI (web UI) of the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protect | 0.7% | — |
| CVE-2019-1915 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Conne | 0.7% | — |
| CVE-2016-9218 | HIGH 8.8 | cisco hybrid_meeting_server A vulnerability in Cisco Hybrid Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against the user of the web interface. More Information: CSCvc28662. Known Affected Releases: 1.0. | 0.7% | — |
| CVE-2009-2073 | MED 6.8 | cisco wrt160n Cross-site request forgery (CSRF) vulnerability in Linksys WRT160N wireless router hardware 1 and firmware 1.02.2 allows remote attackers to hijack the authentication of other users for unspecified requests via unknown vectors, as demonstrated using administra | 0.7% | — |
| CVE-2026-70091 | MED 5.9 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network. | 0.7% | — |
| CVE-2026-59837 | MED 6.6 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1. | 0.7% | — |