57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-29487 | CRIT 9.1 | heimdalsecurity thor An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause a denial of service (DoS) via the Threat To Process Correlation threat prevention module. NOTE: Heimdal asserts this is | 0.7% | — |
| CVE-2023-36711 | HIGH 7.8 | microsoft windows_10_1507 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-34035 | HIGH 7.3 | vmware spring_security Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s Dispatcher | 0.7% | — |
| CVE-2023-35310 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-2160 | MED 6.5 | fedoraproject fedora Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML pa | 0.7% | — |
| CVE-2022-29060 | HIGH 8.1 | fortinet fortiddos A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, 5.1.0 may allow an attacker who managed to retrieve the key from one device to sign JWT tokens for any device. | 0.7% | — |
| CVE-2021-3656 | HIGH 8.8 | fedoraproject fedora A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" | 0.7% | — |
| CVE-2020-3322 | LOW 3.3 | cisco webex_network_recording_player A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnera | 0.7% | — |
| CVE-2020-3319 | LOW 3.3 | cisco webex_network_recording_player A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnera | 0.7% | — |
| CVE-2010-1437 | HIGH 7.0 | debian debian_linux Race condition in the find_keyring_by_name function in security/keys/keyring.c in the Linux kernel 2.6.34-rc5 and earlier allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via keyctl | 0.7% | — |
| CVE-2002-2426 | MED 4.3 | citrix access_essentials Cross-site request forgery (CSRF) vulnerability in Citrix Presentation Server 4.0 and 4.5, MetaFrame Presentation Server 3.0, and Access Essentials 1.0 through 2.0 allows remote attackers to execute arbitrary published applications, and possibly other programs | 0.7% | — |
| CVE-2026-50223 | HIGH 8.8 | apache ofbiz Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template injection attacks that could lead to Remote Code Execution. Thi | 0.7% | — |
| CVE-2026-42778 | CRIT 9.8 | apache mina The fix for CVE-2026-41409 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: The fix for CVE-2024-52046 in Apache MINA AbstractIoBuffer.getObject() was incomplete. The classname allowlist of classes allowed to be des | 0.7% | — |
| CVE-2025-62458 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2025-49695 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.7% | — |
| CVE-2022-49094 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/tls: fix slab-out-of-bounds bug in decrypt_internal The memory size of tls_ctx->rx.iv for AES128-CCM is 12 setting in tls_set_sw_offload(). The return value of crypto_aead_ivsize() for " | 0.7% | — |
| CVE-2024-39534 | MED 5.4 | juniper junos_os_evolved An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the | 0.7% | — |
| CVE-2024-37985 | MED 5.9 | microsoft windows_11_22h2 Windows Kernel Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-38084 | HIGH 7.8 | microsoft officeplus Microsoft OfficePlus Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-23668 | HIGH 8.8 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.7% | — |
| CVE-2023-38163 | HIGH 7.8 | microsoft windows_defender_security_intelligence_updates Windows Defender Attack Surface Reduction Security Feature Bypass | 0.7% | — |
| CVE-2023-32020 | MED 5.6 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0.7% | — |
| CVE-2023-23390 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23378 | HIGH 7.8 | microsoft print_3d Print 3D Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-3113 | MED 5.5 | linux linux_kernel An issue was discovered in the Linux kernel through 5.16-rc6. mtk_vcodec_fw_vpu_init in drivers/media/platform/mtk-vcodec/mtk_vcodec_fw_vpu.c lacks check of the return value of devm_kzalloc() and will cause the null pointer dereference. | 0.7% | — |