IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-47148 MED 5.3 ibm spectrum_protect_plus IBM Storage Protect Plus Server 10.1.0 through 10.1.15.2 Admin Console could allow a remote attacker to obtain sensitive information due to improper validation of unsecured endpoints which could be used in further attacks against the system. IBM X-Force ID: 0.6%
CVE-2023-21572 MED 6.5 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.6%
CVE-2021-33656 MED 6.8 debian debian_linux When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. 0.6%
CVE-2021-34764 MED 4.8 cisco firepower_management_center_virtual_appliance Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an attacker to execute a cross-site scripting (XSS) attack or an open redirect attack. For more information about these vulnerabiliti 0.6%
CVE-2021-31820 HIGH 7.5 octopus octopus_server In Octopus Server after version 2018.8.2 if the Octopus Server Web Request Proxy is configured with authentication, the password is shown in plaintext in the UI. 0.6%
CVE-2021-22117 HIGH 7.8 broadcom rabbitmq_server RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins. 0.6%
CVE-2019-1649 MED 6.7 cisco 15454-m-wse-k9_firmware A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability af 0.6%
CVE-2019-1567 MED 5.4 paloaltonetworks expedition_migration_tool The Expedition Migration tool 1.1.6 and earlier may allow an authenticated attacker to run arbitrary JavaScript or HTML in the User Mapping Settings. 0.6%
CVE-2018-0021 HIGH 8.8 juniper junos If all 64 digits of the connectivity association name (CKN) key or all 32 digits of the connectivity association key (CAK) key are not configured, all remaining digits will be auto-configured to 0. Hence, Juniper devices configured with short MacSec keys are a 0.6%
CVE-2009-3725 HIGH 7.2 canonical ubuntu_linux The connector layer in the Linux kernel before 2.6.31.5 does not require the CAP_SYS_ADMIN capability for certain interaction with the (1) uvesafb, (2) pohmelfs, (3) dst, or (4) dm subsystem, which allows local users to bypass intended access restrictions and 0.6%
CVE-2026-78446 MED 5.3 microsoft windows_10_1607 Use after free in Windows Distributed File System (DFS) allows an authorized attacker to deny service over a network. 0.6%
CVE-2025-49696 HIGH 8.4 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-21184 HIGH 7.0 microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability 0.6%
CVE-2024-56662 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] B 0.6%
CVE-2024-38086 MED 6.4 microsoft azure_kinect_software_development_kit Azure Kinect SDK Remote Code Execution Vulnerability 0.6%
CVE-2023-36719 HIGH 7.8 microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability 0.6%
CVE-2023-36408 HIGH 7.8 microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability 0.6%
CVE-2023-20254 HIGH 7.2 cisco sd-wan_manager A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vul 0.6%
CVE-2023-23482 MED 5.4 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim 0.6%
CVE-2023-22637 MED 6.5 fortinet fortinac An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Mana 0.6%
CVE-2022-42432 MED 4.4 linux linux_kernel This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerabi 0.6%
CVE-2022-33683 MED 5.9 apache pulsar Apache Pulsar Brokers and Proxies create an internal Pulsar Admin Client that does not verify peer TLS certificates, even when tlsAllowInsecureConnection is disabled via configuration. The Pulsar Admin Client's intra-cluster and geo-replication HTTPS connectio 0.6%
CVE-2021-43064 MED 4.3 fortinet fortiweb A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers. 0.6%
CVE-2021-3444 HIGH 7.8 canonical ubuntu_linux The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leadi 0.6%
CVE-2020-3207 MED 6.7 cisco ios_xe A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. T 0.6%