57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21347 | MED 6.0 | microsoft windows_10_1507 Windows Deployment Services Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-20330 | HIGH 8.6 | cisco secure_firewall_threat_defense A vulnerability in the Snort 2 and Snort 3 TCP and UDP detection engine of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Appliances could allow an unauthenticated, remote attacker to cause memory corruption, which could cause th | 0.7% | — |
| CVE-2023-52513 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: Fix connection failure handling In case immediate MPA request processing fails, the newly created endpoint unlinks the listening endpoint and is ready to be dropped. This special c | 0.7% | — |
| CVE-2023-2316 | HIGH 7.4 | typora typora Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/<absolute-path>". This vulnerability can be exploited if a user opens a malicious ma | 0.7% | — |
| CVE-2022-45434 | MED 5.9 | dahuasecurity dhi-dss4004-s2_firmware Some Dahua software products have a vulnerability of unauthenticated un-throttled ICMP requests on remote DSS Server. After bypassing the firewall access control policy, by sending a specific crafted packet to the vulnerable interface, an attacker could exploi | 0.7% | — |
| CVE-2022-32414 | MED 5.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_vmcode_interpreter at src/njs_vmcode.c. | 0.7% | — |
| CVE-2022-31307 | MED 5.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_string_offset at src/njs_string.c. | 0.7% | — |
| CVE-2022-31306 | MED 5.5 | f5 njs Nginx NJS v0.7.2 was discovered to contain a segmentation violation in the function njs_array_convert_to_slow_array at src/njs_array.c. | 0.7% | — |
| CVE-2021-31364 | MED 5.9 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with a Race Condition in the flow daemon (flowd) of Juniper Networks Junos OS on SRX300 Series, SRX500 Series, SRX1500, and SRX5000 Series with SPC2 allows an unauthenticated networ | 0.7% | — |
| CVE-2020-8648 | HIGH 7.1 | broadcom brocade_fabric_operating_system_firmware There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. | 0.7% | — |
| CVE-2019-20362 | HIGH 7.8 | teradici pcoip_client In Teradici PCoIP Agent before 19.08.1 and PCoIP Client before 19.08.3, an unquoted service path can cause execution of %PROGRAMFILES(X86)%\Teradici\PCoIP.exe instead of the intended pcoip_vchan_printing_svc.exe file. | 0.7% | — |
| CVE-2018-15373 | HIGH 7.4 | cisco ios A vulnerability in the implementation of Cisco Discovery Protocol functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust memory on an affected device, resulting in a denial of service (DoS) co | 0.7% | — |
| CVE-2014-0205 | MED 6.9 | linux linux_kernel The futex_wait function in kernel/futex.c in the Linux kernel before 2.6.37 does not properly maintain a certain reference count during requeue operations, which allows local users to cause a denial of service (use-after-free and system crash) or possibly gain | 0.7% | — |
| CVE-2013-2930 | LOW 3.6 | linux linux_kernel The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application. | 0.7% | — |
| CVE-2010-2506 | LOW 2.9 | cisco linksys_firmware Cross-site scripting (XSS) vulnerability in debug.cgi in Linksys WAP54Gv3 firmware 3.05.03 and 3.04.03 allows remote attackers to inject arbitrary web script or HTML via the data1 parameter. | 0.7% | — |
| CVE-2026-56171 | HIGH 7.1 | microsoft remote_desktop_web_client Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-44914 | HIGH 7.2 | apache nifi Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges required | 0.7% | — |
| CVE-2024-53066 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfs: Fix KMSAN warning in decode_getfattr_attrs() Fix the following KMSAN warning: CPU: 1 UID: 0 PID: 7651 Comm: cp Tainted: G B Tainted: [B]=BAD_PAGE Hardware name: QEMU Standard PC (Q3 | 0.7% | — |
| CVE-2024-30471 | LOW 3.7 | apache streampipes Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache StreamPipes in user self-registration. This allows an attacker to potentially request the creation of multiple accounts with the same email address until the email address is registered, | 0.7% | — |
| CVE-2023-20866 | MED 6.5 | vmware spring_session In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensitive information to those who have access to the application logs and can be used for session hijacking. Specifically, an application i | 0.7% | — |
| CVE-2022-22245 | MED 4.3 | juniper junos A Path Traversal vulnerability in the J-Web component of Juniper Networks Junos OS allows an authenticated attacker to upload arbitrary files to the device by bypassing validation checks built into Junos OS. The attacker should not be able to execute the file | 0.7% | — |
| CVE-2022-27502 | HIGH 7.8 | realvnc vnc_server RealVNC VNC Server 6.9.0 through 5.1.0 for Windows allows local privilege escalation because an installer repair operation executes %TEMP% files as SYSTEM. | 0.7% | — |
| CVE-2022-22157 | HIGH 7.2 | juniper junos A traffic classification vulnerability in Juniper Networks Junos OS on the SRX Series Services Gateways may allow an attacker to bypass Juniper Deep Packet Inspection (JDPI) rules and access unauthorized networks or resources, when 'no-syn-check' is enabled on | 0.7% | — |
| CVE-2022-21869 | HIGH 7.0 | microsoft windows_10 Clipboard User Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-21861 | HIGH 7.0 | microsoft windows_10 Task Flow Data Engine Elevation of Privilege Vulnerability | 0.7% | — |