57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43450 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 0.6% | — |
| CVE-2024-26362 | HIGH 8.8 | enpass password_manager HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note. | 0.6% | — |
| CVE-2024-26641 | HIGH 8.6 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv() syzbot found __ip6_tnl_rcv() could access unitiliazed data [1]. Call pskb_inet_may_pull() to fix this, and initialize ipv6h var | 0.6% | — |
| CVE-2023-27863 | MED 4.4 | ibm spectrum_protect IBM Spectrum Protect Plus Server 10.1.13, under specific configurations, could allow an elevated user to obtain SMB credentials that may be used to access vSnap data stores. IBM X-Force ID: 249325. | 0.6% | — |
| CVE-2023-20131 | MED 6.5 | cisco evolved_programmable_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow a remote attacker to obtain privileged information and conduct cross-site scripting (XSS) and cross-s | 0.6% | — |
| CVE-2023-23778 | MED 4.9 | fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated user to obtain unauthorized access to files and data via specifically crafted web requests. | 0.6% | — |
| CVE-2022-41336 | MED 6.8 | fortinet fortiportal An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiPortal versions 6.0.0 through 6.0.11 and all versions of 5.3, 5.2, 5.1, 5.0 management interface may allow a remote authenticated attacker to perform a stored cross s | 0.6% | — |
| CVE-2022-38434 | HIGH 7.8 | adobe photoshop Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that | 0.6% | — |
| CVE-2020-24562 | HIGH 7.8 | trendmicro officescan A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ab | 0.6% | — |
| CVE-2019-19480 | MED 4.6 | opensc_project opensc An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/pkcs15-prkey.c has an incorrect free operation in sc_pkcs15_decode_prkdf_entry. | 0.6% | — |
| CVE-2019-5694 | MED 6.5 | nvidia gpu_driver NVIDIA Windows GPU Display Driver, R390 driver version, contains a vulnerability in NVIDIA Control Panel in which it incorrectly loads Windows system DLLs without validating the path or signature (also known as a binary planting or DLL preloading attack), whic | 0.6% | — |
| CVE-2012-6026 | MED 6.1 | cisco aironet_access_point_software The HTTP Profiler on the Cisco Aironet Access Point with software 15.2 and earlier does not properly manage buffers, which allows remote attackers to cause a denial of service (device reload) via crafted HTTP requests, aka Bug ID CSCuc62460. | 0.6% | — |
| CVE-2026-73016 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-71328 | HIGH 8.8 | microsoft .net Heap-based buffer overflow in Visual Studio allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-8505 | CRIT 9.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuratio | 0.6% | — |
| CVE-2025-59286 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2025-59272 | CRIT 9.3 | microsoft 365_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally. | 0.6% | — |
| CVE-2025-59252 | CRIT 9.3 | microsoft 365_word_copilot Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2024-26009 | HIGH 8.1 | fortinet fortios An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, FortiOS 6.0 all versions, FortiPAM 1.2.0, FortiPAM 1.1.0 through 1.1.2, FortiPAM 1.0.0 through 1.0.3, Fo | 0.6% | — |
| CVE-2025-26688 | HIGH 7.8 | microsoft windows_10_1507 Stack-based buffer overflow in Microsoft Virtual Hard Drive allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-24995 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-21267 | MED 4.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.6% | — |
| CVE-2024-33510 | MED 4.3 | fortinet fortios An improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2. | 0.6% | — |
| CVE-2024-49999 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: afs: Fix the setting of the server responding flag In afs_wait_for_operation(), we set transcribe the call responded flag to the server record that we used after doing the fileserver iterati | 0.6% | — |
| CVE-2023-6794 | MED 5.5 | paloaltonetworks pan-os An arbitrary file upload vulnerability in Palo Alto Networks PAN-OS software enables an authenticated read-write administrator with access to the web interface to disrupt system processes and potentially execute arbitrary code with limited privileges on the fi | 0.6% | — |