57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-0459 | MED 6.5 | linux linux_kernel Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend up | 0.6% | — |
| CVE-2023-22399 | HIGH 7.5 | juniper junos When sFlow is enabled and it monitors a packet forwarded via ECMP, a buffer management vulnerability in the dcpfe process of Juniper Networks Junos OS on QFX10K Series systems allows an attacker to cause the Packet Forwarding Engine (PFE) to crash and restart | 0.6% | — |
| CVE-2022-41813 | MED 6.5 | f5 big-ip_advanced_firewall_manager In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate. | 0.6% | — |
| CVE-2022-41770 | MED 6.5 | f5 big-ip_access_policy_manager In BIG-IP versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.7, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ all versions of 8.x and 7.x, an authenticated iControl REST user can cause an increase in memory resource ut | 0.6% | — |
| CVE-2022-31672 | HIGH 7.2 | vmware vrealize_operations VMware vRealize Operations contains a privilege escalation vulnerability. A malicious actor with administrative network access can escalate privileges to root. | 0.6% | — |
| CVE-2021-39018 | MED 4.3 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose sensitive information in a SQL error message that could aid in further attacks against the system. IBM X-Force ID: 213726. | 0.6% | — |
| CVE-2020-29013 | MED 5.4 | fortinet fortisandbox An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt the sniffer via specifically crafted requests. | 0.6% | — |
| CVE-2021-1507 | MED 6.4 | cisco sd-wan_vmanage A vulnerability in an API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against users of the application web-based interface. This vulnerability exists because the API does | 0.6% | — |
| CVE-2019-17052 | LOW 3.3 | canonical ubuntu_linux ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768. | 0.6% | — |
| CVE-2014-9803 | HIGH 7.8 | google android arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android | 0.6% | — |
| CVE-2011-4847 | HIGH 7.5 | parallels parallels_plesk_panel SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/. | 0.6% | — |
| CVE-2005-4825 | MED 5.7 | cisco network_admission_control_manager_and_server_system_software Cisco Clean Access 3.5.5 and earlier on the Secure Smart Manager allows remote attackers to bypass authentication and cause a denial of service (disk consumption), or make unauthorized files accessible, by uploading files through requests to certain JSP script | 0.6% | — |
| CVE-2026-61486 | CRIT 9.8 | apache lucy ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find a | 0.6% | — |
| CVE-2026-50524 | HIGH 7.5 | microsoft .net Improper validation of specified type of input in .NET Framework allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2024-43508 | MED 5.5 | microsoft windows_11_22h2 Windows Graphics Component Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-43500 | MED 5.5 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-41694 | MED 4.9 | f5 big-ip_access_policy_manager In BIG-IP versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, and BIG-IQ versions 8.x before 8.2.0.1 and all versions of 7.x, when an SSL key is imported on a BIG-IP or BIG-IQ system, undisclosed input can c | 0.6% | — |
| CVE-2022-22050 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-21862 | HIGH 7.0 | microsoft windows_10 Windows Application Model Core API Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21859 | HIGH 7.0 | microsoft windows_10 Windows Accounts Control Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-3043 | HIGH 7.5 | paloaltonetworks prisma_cloud A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web inte | 0.6% | — |
| CVE-2020-27729 | MED 6.1 | f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2, an undisclosed link on the BIG-IP APM virtual server allows a malicious user to build an open redirect URI. | 0.6% | — |
| CVE-2019-1893 | HIGH 7.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient i | 0.6% | — |
| CVE-2026-62822 | HIGH 8.8 | microsoft windows_10_1607 Integer overflow or wraparound in Windows GDI+ allows an unauthorized attacker to execute code over a network. | 0.6% | — |