IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-38029 HIGH 7.0 microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability 0.6%
CVE-2022-20916 MED 6.1 cisco iot_control_center A vulnerability in the web-based management interface of Cisco IoT Control Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based ma 0.6%
CVE-2022-25372 HIGH 7.8 pritunl pritunl-client-electron Pritunl Client through 1.2.3019.52 on Windows allows local privilege escalation, related to an ACL entry for CREATOR OWNER in platform_windows.go. 0.6%
CVE-2021-31171 MED 4.1 microsoft sharepoint_foundation Microsoft SharePoint Information Disclosure Vulnerability 0.6%
CVE-2021-0258 MED 5.9 juniper junos A vulnerability in the forwarding of transit TCPv6 packets received on the Ethernet management interface of Juniper Networks Junos OS allows an attacker to trigger a kernel panic, leading to a Denial of Service (DoS). Continued receipt and processing of these 0.6%
CVE-2021-1682 HIGH 7.0 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 0.6%
CVE-2018-13375 MED 6.1 fortinet fortianalyzer An Improper Neutralization of Script-Related HTML Tags in Fortinet FortiAnalyzer 5.6.0 and below and FortiManager 5.6.0 and below allows an attacker to send DHCP request containing malicious scripts in the HOSTNAME parameter. The malicious script code is execu 0.6%
CVE-2015-9281 MED 6.1 sas web_infrastructure_platform Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. 0.6%
CVE-2018-0054 MED 6.5 juniper junos On QFX5000 Series and EX4600 switches, a high rate of Ethernet pause frames or an ARP packet storm received on the management interface (fxp0) can cause egress interface congestion, resulting in routing protocol packet drops, such as BGP, leading to peering fl 0.6%
CVE-2014-3403 MED 5.0 cisco ios_xe The Autonomic Networking Infrastructure (ANI) component in Cisco IOS XE does not properly validate certificates, which allows remote attackers to spoof devices via crafted messages, aka Bug ID CSCuq22647. 0.6%
CVE-2013-1189 MED 5.7 cisco ubr10012 Cisco Universal Broadband (aka uBR) 10000 series routers, when an IPv4/IPv6 dual-stack modem is used, allow remote attackers to cause a denial of service (routing-engine reload) via unspecified changes to IP address assignments, aka Bug ID CSCue15313. 0.6%
CVE-2011-0588 MED 6.9 adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than 0.6%
CVE-2011-0570 MED 6.9 adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than 0.6%
CVE-2003-0462 LOW 1.2 linux linux_kernel A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash). 0.6%
CVE-2026-69679 MED 5.7 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. 0.6%
CVE-2026-69637 MED 5.7 microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. 0.6%
CVE-2026-44913 HIGH 7.2 apache nifi Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potent 0.6%
CVE-2026-48895 HIGH 7.2 apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3 0.6%
CVE-2026-50632 HIGH 8.1 apache cxf A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users 0.6%
CVE-2026-21529 MED 5.7 microsoft azure_hdinsight Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network. 0.6%
CVE-2024-43513 MED 6.4 microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability 0.6%
CVE-2024-42110 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx() The following is emitted when using idxd (DSA) dmanegine as the data mover for ntb_transport that ntb_netde 0.6%
CVE-2024-37973 HIGH 8.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6%
CVE-2023-52834 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: atl1c: Work around the DMA RX overflow issue This is based on alx driver commit 881d0327db37 ("net: alx: Work around the DMA RX overflow issue"). The alx and atl1c drivers had RX overflow e 0.6%
CVE-2024-26826 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix data re-injection from stale subflow When the MPTCP PM detects that a subflow is stale, all the packet scheduler must re-inject all the mptcp-level unacked data. To avoid acquirin 0.6%