57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0024 | MED 5.4 | juniper advanced_threat_prevention A persistent cross-site scripting (XSS) vulnerability in the Email Collectors menu of Juniper ATP may allow authenticated user to inject arbitrary script and steal sensitive data and credentials from a web administration session, possibly tricking a follow-on | 0.6% | — |
| CVE-2013-6763 | MED 6.9 | linux linux_kernel The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, | 0.6% | — |
| CVE-2026-84001 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows Key Distribution Center allows an unauthorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-70332 | CRIT 9.6 | microsoft sharepoint_online Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-48586 | HIGH 7.5 | apache thrift Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift C++, Java, Python, Go, D, C/GLib bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the is | 0.6% | — |
| CVE-2026-43869 | HIGH 7.3 | apache thrift Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0.6% | — |
| CVE-2026-30897 | MED 6.6 | fortinet fortiweb A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can bypass sta | 0.6% | — |
| CVE-2026-24640 | MED 6.6 | fortinet fortiweb A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated att | 0.6% | — |
| CVE-2025-48208 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman | 0.6% | — |
| CVE-2024-46670 | HIGH 7.5 | fortinet fortios An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption le | 0.6% | — |
| CVE-2024-53206 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: Fix use-after-free of nreq in reqsk_timer_handler(). The cited commit replaced inet_csk_reqsk_queue_drop_and_put() with __inet_csk_reqsk_queue_drop() and reqsk_put() in reqsk_timer_hand | 0.6% | — |
| CVE-2024-49051 | HIGH 7.8 | microsoft pc_manager Microsoft PC Manager Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-9467 | MED 6.1 | paloaltonetworks expedition A reflected XSS vulnerability in Palo Alto Networks Expedition enables execution of malicious JavaScript in the context of an authenticated Expedition user's browser if that user clicks on a malicious link, allowing phishing attacks that could lead to Expediti | 0.6% | — |
| CVE-2024-43551 | HIGH 7.8 | microsoft windows_10_1607 Windows Storage Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-38098 | HIGH 7.8 | microsoft azure_connected_machine_agent Azure Connected Machine Agent Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-36831 | HIGH 7.5 | juniper junos An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading | 0.6% | — |
| CVE-2023-20899 | HIGH 7.5 | vmware sd-wan_edge_firmware VMware SD-WAN (Edge) contains a bypass authentication vulnerability. An unauthenticated attacker can download the Diagnostic bundle of the application under VMware SD-WAN Management. | 0.6% | — |
| CVE-2022-34352 | MED 6.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403. | 0.6% | — |
| CVE-2023-21820 | HIGH 7.4 | microsoft windows_10 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-22753 | HIGH 7.1 | mozilla firefox A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directory. This could have been used to escalate to SYSTEM access.<br>*This bug only affects Firefox on Windows. Other | 0.6% | — |
| CVE-2022-26240 | MED 6.5 | beckmancoulter remisol_advance The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data. | 0.6% | — |
| CVE-2021-43207 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-32602 | MED 5.8 | fortinet fortiportal An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote a | 0.6% | — |
| CVE-2021-1135 | MED 4.6 | cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the | 0.6% | — |
| CVE-2019-19966 | MED 4.6 | debian debian_linux In the Linux kernel before 5.1.6, there is a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service, aka CID-dea37a972655. | 0.6% | — |