57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-62210 | HIGH 8.7 | microsoft dynamics_365 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Field Service (online) allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2025-25008 | HIGH 7.1 | microsoft windows_server_2016 Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-46669 | LOW 3.5 | fortinet fortios An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, result | 0.6% | — |
| CVE-2024-26890 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: fix out of bounds memory access The problem is detected by KASAN. btrtl driver uses private hci data to store 'struct btrealtek_data'. If btrtl driver is used with btusb, t | 0.6% | — |
| CVE-2024-20709 | MED 5.5 | adobe acrobat Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current | 0.6% | — |
| CVE-2023-32032 | MED 6.5 | microsoft .net .NET and Visual Studio Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-26795 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-1403 | HIGH 7.4 | cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site WebSocket hijacking (CSWSH) attack and cause a denial of service (DoS) condition on an affected device. This vulnerability is | 0.6% | — |
| CVE-2019-13163 | MED 5.9 | fujitsu celsius_firmware The Fujitsu TLS library allows a man-in-the-middle attack. This affects Interstage Application Development Cycle Manager V10 and other versions, Interstage Application Server V12 and other versions, Interstage Business Application Manager V2 and other versions | 0.6% | — |
| CVE-2019-15223 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver. | 0.6% | — |
| CVE-2019-1958 | HIGH 8.8 | cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to insufficient CSRF protect | 0.6% | — |
| CVE-2014-1874 | MED 4.9 | canonical ubuntu_linux The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context. | 0.6% | — |
| CVE-2026-59245 | HIGH 8.1 | apache apache-airflow-providers-fab In the Apache Airflow FAB auth manager, a DAG whose `dag_id` is `DAGs` collided with the global all-DAGs permission resource name produced by `resource_name()`, so a user granted per-DAG `access_control` on that one DAG was silently granted the global all-DAGs | 0.6% | — |
| CVE-2026-41610 | MED 6.3 | microsoft visual_studio_code Improper neutralization of input during web page generation ('cross-site scripting') in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally. | 0.6% | — |
| CVE-2025-52983 | HIGH 7.2 | juniper junos A UI Discrepancy for Security Feature vulnerability in the UI of Juniper Networks Junos OS on VM Host systems allows a network-based, unauthenticated attacker to access the device. On VM Host Routing Engines (RE), even if the configured public key for root | 0.6% | — |
| CVE-2022-49110 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: revisit gc autotuning as of commit 4608fdfc07e1 ("netfilter: conntrack: collect all entries in one cycle") conntrack gc was changed to run every 2 minutes. On systems | 0.6% | — |
| CVE-2024-41765 | MED 6.5 | ibm engineering_lifecycle_optimization_publishing IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the | 0.6% | — |
| CVE-2024-47497 | HIGH 7.5 | juniper junos An Uncontrolled Resource Consumption vulnerability in the http daemon (httpd) of Juniper Networks Junos OS on SRX Series, QFX Series, MX Series and EX Series allows an unauthenticated, network-based attacker to cause Denial-of-Service (DoS). An attacker can s | 0.6% | — |
| CVE-2024-30364 | LOW 3.3 | foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this | 0.6% | — |
| CVE-2023-45177 | MED 5.3 | ibm mq IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS and 9.3 CD is vulnerable to a denial-of-service attack due to an error within the MQ clustering logic. IBM X-Force ID: 268066. | 0.6% | — |
| CVE-2023-27555 | MED 5.1 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.5 is vulnerable to a denial of service when attempting to use ACR client affinity for unfenced DRDA federation wrappers. IBM X-Force ID: 249187. | 0.6% | — |
| CVE-2023-21763 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-4439 | HIGH 8.8 | google chrome Use after free in Aura in Google Chrome on Windows prior to 108.0.5359.124 allowed a remote attacker who convinced the user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions. (Chromium security severity: | 0.6% | — |
| CVE-2022-36402 | MED 6.3 | linux linux_kernel An integer overflow vulnerability was found in vmwgfx driver in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in GPU component of Linux kernel with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the system to gain p | 0.6% | — |
| CVE-2022-22411 | MED 6.5 | ibm spectrum_scale_data_access_services IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow the attacker to manipulate cluster resources due to excessive permissions. IBM X-Force ID: 223016. | 0.6% | — |