57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-23171 | MED 5.9 | atlasvpn atlasvpn AtlasVPN - Privilege Escalation Lack of proper security controls on named pipe messages can allow an attacker with low privileges to send a malicious payload and gain SYSTEM permissions on a windows computer where the AtlasVPN client is installed. | 0.7% | — |
| CVE-2022-0011 | MED 6.5 | paloaltonetworks pan-os PAN-OS software provides options to exclude specific websites from URL category enforcement and those websites are blocked or allowed (depending on your rules) regardless of their associated URL category. This is done by creating a custom URL category list or | 0.7% | — |
| CVE-2022-21902 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-1699 | MED 6.7 | cisco secure_firewall_management_center A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerabil | 0.7% | — |
| CVE-2015-4940 | LOW 2.1 | apache ambari Apache Ambari before 2.1, as used in IBM Infosphere BigInsights 4.x before 4.1, stores a cleartext BigSheets password in a configuration file, which allows local users to obtain sensitive information by reading this file. | 0.7% | — |
| CVE-2026-62823 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over an adjacent network. | 0.7% | — |
| CVE-2026-47294 | HIGH 8.0 | microsoft sharepoint_server Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-35433 | HIGH 7.3 | microsoft .net Improper input validation in .NET allows an unauthorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2026-24713 | CRIT 9.8 | apache iotdb Improper Input Validation vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.7, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.7 or 2.0.7, which fixes the issue. | 0.7% | — |
| CVE-2024-20455 | HIGH 8.6 | cisco ios_xe A vulnerability in the process that classifies traffic that is going to the Unified Threat Defense (UTD) component of Cisco IOS XE Software in controller mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an af | 0.7% | — |
| CVE-2024-35864 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_lease_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. | 0.7% | — |
| CVE-2024-35863 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. | 0.7% | — |
| CVE-2024-35862 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_network_name_deleted() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. | 0.7% | — |
| CVE-2024-35861 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in cifs_signal_cifsd_for_reconnect() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. | 0.7% | — |
| CVE-2024-30335 | HIGH 7.1 | foxit pdf_editor Foxit PDF Reader AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit th | 0.7% | — |
| CVE-2022-31739 | HIGH 8.8 | mozilla firefox When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Oth | 0.7% | — |
| CVE-2022-41552 | CRIT 9.8 | hitachi infrastructure_analytics_advisor Server-Side Request Forgery (SSRF) vulnerability in Hitachi Infrastructure Analytics Advisor on Linux (Data Center Analytics, Analytics probe components), Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyze | 0.7% | — |
| CVE-2021-24021 | MED 4.3 | fortinet fortianalyzer An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the column settings o | 0.7% | — |
| CVE-2017-6603 | MED 6.5 | cisco asr_900_series_firmware A vulnerability in Cisco ASR 903 or ASR 920 Series Devices running with an RSP2 card could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on a targeted system because of incorrect IPv6 Packet Processing. More Informati | 0.7% | — |
| CVE-2011-1079 | MED 5.4 | linux linux_kernel The bnep_sock_ioctl function in net/bluetooth/bnep/sock.c in the Linux kernel before 2.6.39 does not ensure that a certain device field ends with a '\0' character, which allows local users to obtain potentially sensitive information from kernel stack memory, o | 0.7% | — |
| CVE-2026-65769 | MED 6.5 | microsoft teams Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-44416 | CRIT 9.8 | apache ranger Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.7% | — |
| CVE-2026-20943 | HIGH 7.0 | microsoft office Untrusted search path in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2025-26634 | HIGH 7.5 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Core Messaging allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2022-49075 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: btrfs: fix qgroup reserve overflow the qgroup limit We use extent_changeset->bytes_changed in qgroup_reserve_data() to record how many bytes we set for EXTENT_QGROUP_RESERVED state. Currentl | 0.7% | — |