IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-35795 HIGH 7.8 microsoft windows_10 Windows Error Reporting Service Elevation of Privilege Vulnerability 0.7%
CVE-2022-30132 HIGH 7.8 microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability 0.7%
CVE-2019-19965 MED 4.7 canonical ubuntu_linux In the Linux kernel through 5.4.6, there is a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition, aka CID-f70267f379b5. 0.7%
CVE-2019-5538 MED 5.9 vmware vcenter_server Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to inter 0.7%
CVE-2019-5537 MED 5.9 vmware vcenter_server Sensitive information disclosure vulnerability resulting from a lack of certificate validation during the File-Based Backup and Restore operations of VMware vCenter Server Appliance (6.7 before 6.7u3a and 6.5 before 6.5u3d) may allow a malicious actor to inter 0.7%
CVE-2018-7191 MED 5.5 linux linux_kernel In the tun subsystem in the Linux kernel before 4.13.14, dev_get_valid_name is not called before register_netdevice. This allows local users to cause a denial of service (NULL pointer dereference and panic) via an ioctl(TUNSETIFF) call with a dev name containi 0.7%
CVE-2013-2929 LOW 3.3 linux linux_kernel The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c an 0.7%
CVE-2026-42782 HIGH 7.2 apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class sta 0.7%
CVE-2026-20828 MED 4.6 microsoft windows_10_1607 Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information with a physical attack. 0.7%
CVE-2025-47169 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.7%
CVE-2024-56736 MED 6.5 apache hertzbeat Server-Side Request Forgery (SSRF) vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue. 0.7%
CVE-2025-26865 LOW 3.5 apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.   It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which 0.7%
CVE-2024-57973 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof 0.7%
CVE-2024-38210 HIGH 7.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7%
CVE-2024-38209 HIGH 7.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7%
CVE-2022-48829 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix NFSv3 SETATTR/CREATE's handling of large file sizes iattr::ia_size is a loff_t, so these NFSv3 procedures must be careful to deal with incoming client size values that are larger t 0.7%
CVE-2024-27254 MED 5.3 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 federated server is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 283813. 0.7%
CVE-2023-36860 HIGH 7.1 intel unison_software Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access. 0.7%
CVE-2023-20227 HIGH 8.6 cisco ios_xe A vulnerability in the Layer 2 Tunneling Protocol (L2TP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of c 0.7%
CVE-2023-20176 MED 5.8 cisco catalyst_9124_firmware A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacker could exploit this 0.7%
CVE-2023-20033 HIGH 8.6 cisco ios_xe A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vul 0.7%
CVE-2023-4273 MED 6.0 debian debian_linux A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file name reconstruction function, which is responsible for reading file name entries from a directory index and merging file name parts belonging t 0.7%
CVE-2022-35842 LOW 3.7 fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6 and versions 6.4.0 through 6.4.9 may allow a remote unauthenticated attacker to gain information about LDAP an 0.7%
CVE-2022-24484 MED 5.5 microsoft windows_server_2012 Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability 0.7%
CVE-2022-23268 MED 6.5 microsoft windows_11 Windows Hyper-V Denial of Service Vulnerability 0.7%