57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1127 | MED 5.4 | cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The | 0.6% | — |
| CVE-2011-1017 | HIGH 7.2 | canonical ubuntu_linux Heap-based buffer overflow in the ldm_frag_add function in fs/partitions/ldm.c in the Linux kernel 2.6.37.2 and earlier might allow local users to gain privileges or obtain sensitive information via a crafted LDM partition table. | 0.6% | — |
| CVE-2026-12443 | HIGH 8.8 | google chrome Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical) | 0.6% | — |
| CVE-2026-27303 | CRIT 9.6 | adobe connect Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a | 0.6% | — |
| CVE-2025-65115 | HIGH 8.8 | hitachi job_management_partner_1\/it_desktop_management-manager Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on | 0.6% | — |
| CVE-2025-21337 | LOW 3.3 | microsoft windows_10_1507 Windows NTFS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-52515 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: Do not call scsi_done() from srp_abort() After scmd_eh_abort_handler() has called the SCSI LLD eh_abort_handler callback, it performs one of the following actions: * Call scsi_queu | 0.6% | — |
| CVE-2023-49321 | MED 5.3 | f-secure atlant Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSec | 0.6% | — |
| CVE-2023-4622 | HIGH 7.8 | debian debian_linux A use-after-free vulnerability in the Linux kernel's af_unix component can be exploited to achieve local privilege escalation. The unix_stream_sendpage() function tries to add data to the last skb in the peer's recv queue without locking the queue. Thus the | 0.6% | — |
| CVE-2023-20018 | HIGH 8.6 | cisco ip_phone_7800_firmware A vulnerability in the web-based management interface of Cisco IP Phone 7800 and 8800 Series Phones could allow an unauthenticated, remote attacker to bypass authentication on an affected device. This vulnerability is due to insufficient validation of user- | 0.6% | — |
| CVE-2022-30305 | LOW 3.7 | fortinet fortideceptor An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions 4.2.0, 4.1.0 through 4.1.1, 4.0.0 through 4.0.2, 3.3.0 through 3.3.3, 3.2.0 through 3.2.2,3.1.0 through 3.1.1 | 0.6% | — |
| CVE-2022-37997 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-36772 | MED 6.5 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that should only be available to a privileged user. | 0.6% | — |
| CVE-2021-36178 | MED 4.3 | fortinet fortisdnconnector A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credential information via configuration page lookup. | 0.6% | — |
| CVE-2019-15117 | HIGH 7.8 | linux linux_kernel parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access. | 0.6% | — |
| CVE-2016-6198 | MED 5.5 | linux linux_kernel The filesystem layer in the Linux kernel before 4.5.5 proceeds with post-rename operations after an OverlayFS file is renamed to a self-hardlink, which allows local users to cause a denial of service (system crash) via a rename system call, related to fs/namei | 0.6% | — |
| CVE-2015-0731 | MED 6.1 | cisco ios The ISDN implementation in Cisco IOS 15.3S allows remote attackers to cause a denial of service (device reload) via malformed Q931 SETUP messages, aka Bug ID CSCut37890. | 0.6% | — |
| CVE-2013-4262 | LOW 2.4 | apache subversion svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The | 0.6% | — |
| CVE-2013-6368 | MED 6.2 | linux linux_kernel The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address. | 0.6% | — |
| CVE-2013-6705 | MED 6.1 | cisco ios The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device reload) via a crafted sequence of ARP packets, aka Bug ID CSCuh38133. | 0.6% | — |
| CVE-2026-66308 | MED 6.5 | microsoft skype_for_business_server Out-of-bounds read in Skype for Business allows an authorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-67641 | MED 6.5 | microsoft sql_server_2022 Integer overflow or wraparound in SQL Server allows an authorized attacker to deny service over a network. | 0.6% | — |
| CVE-2026-65083 | CRIT 9.9 | nvidia openshell NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, infor | 0.6% | — |
| CVE-2026-45859 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_queue: do shared-unconfirmed check before segmentation Ulrich reports a regression with nfqueue: If an application did not set the 'F_GSO' capability flag and a gso pac | 0.6% | — |
| CVE-2025-33042 | HIGH 7.3 | apache avro Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Avro Java SDK when generating specific records from untrusted Avro schemas. This issue affects Apache Avro Java SDK: all versions through 1.11.4 and version 1.12.0. Users are r | 0.6% | — |