IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-2433 MED 4.3 paloaltonetworks pan-os An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents th 0.6%
CVE-2023-48633 HIGH 7.8 adobe after_effects Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in 0.6%
CVE-2020-2016 HIGH 7.0 paloaltonetworks pan-os A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege adminis 0.6%
CVE-2014-7825 HIGH 7.8 linux linux_kernel kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protectio 0.6%
CVE-2026-11311 HIGH 8.1 f5 nginx_gateway_fabric When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the NginxProxy Custom Resource Definition serve 0.6%
CVE-2025-55247 HIGH 7.3 microsoft .net Improper link resolution before file access ('link following') in .NET allows an authorized attacker to elevate privileges locally. 0.6%
CVE-2025-48804 MED 6.8 microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. 0.6%
CVE-2025-21357 MED 6.7 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 0.6%
CVE-2024-47749 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/cxgb4: Added NULL check for lookup_atid The lookup_atid() function can return NULL if the ATID is invalid or does not exist in the identifier table, which could lead to dereferencing a 0.6%
CVE-2024-38246 HIGH 7.0 microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability 0.6%
CVE-2024-28924 MED 6.7 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.6%
CVE-2023-38729 MED 6.8 ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to sensitive information disclosure when using ADMIN_CMD with IMPORT or EXPORT. 0.6%
CVE-2023-47536 LOW 3.1 fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacke 0.6%
CVE-2021-34475 MED 5.4 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.6%
CVE-2023-28968 MED 5.3 juniper appid_service_sigpack An Improperly Controlled Sequential Memory Allocation vulnerability in the Juniper Networks Deep Packet Inspection-Decoder (JDPI-Decoder) Application Signature component of Junos OS's AppID service on SRX Series devices will stop the JDPI-Decoder from identify 0.6%
CVE-2019-17056 LOW 3.3 linux linux_kernel llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-3a359798b176. 0.6%
CVE-2018-0194 HIGH 7.8 cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of 0.6%
CVE-2018-0193 HIGH 7.8 cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of 0.6%
CVE-2018-0185 HIGH 7.8 cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of 0.6%
CVE-2018-0182 HIGH 7.8 cisco ios_xe Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of 0.6%
CVE-2026-77495 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-73023 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-73013 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-65679 HIGH 8.1 microsoft windows_10_1607 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. 0.6%
CVE-2026-7872 HIGH 7.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user. 0.6%