58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-15326 | HIGH 7.5 | f5 big-ip_access_policy_manager In some situations on BIG-IP APM 14.0.0-14.0.0.2, 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.2, the CRLDP Auth access policy agent may treat revoked certificates as valid when the BIG-IP APM system fails to download a new Certificate Revocation List. | 0.6% | — |
| CVE-2018-7268 | MED 5.5 | magnicomp sysinfo MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file p | 0.6% | — |
| CVE-2026-48303 | CRIT 10.0 | adobe campaign Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inter | 0.6% | — |
| CVE-2026-21906 | HIGH 7.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated network-based attacker sending a specific ICMP packet through a GRE tunnel to cause the PFE | 0.6% | — |
| CVE-2025-59509 | MED 5.5 | microsoft windows_10_1809 Insertion of sensitive information into sent data in Windows Speech allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-45100 | MED 4.9 | ibm security_qradar_edr IBM Security ReaQta 3.12 could allow a privileged user to cause a denial of service by sending multiple administration requests due to improper allocation of resources. | 0.6% | — |
| CVE-2024-53177 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: prevent use-after-free due to open_cached_dir error paths If open_cached_dir() encounters an error parsing the lease from the server, the error handling may race with receiving a lease | 0.6% | — |
| CVE-2023-44255 | MED 4.1 | fortinet fortianalyzer An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event | 0.6% | — |
| CVE-2024-20500 | MED 5.8 | cisco meraki_mx100_firmware A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a DoS condition in the AnyConnect service on an affected device. This vulnera | 0.6% | — |
| CVE-2018-10323 | MED 5.5 | canonical ubuntu_linux The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a crafted xfs image. | 0.6% | — |
| CVE-2016-4581 | MED 5.5 | canonical ubuntu_linux fs/pnode.c in the Linux kernel before 4.5.4 does not properly traverse a mount propagation tree in a certain case involving a slave mount, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a crafted series of mount s | 0.6% | — |
| CVE-2016-4482 | MED 6.2 | canonical ubuntu_linux The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl c | 0.6% | — |
| CVE-2016-3156 | MED 5.5 | canonical ubuntu_linux The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses. | 0.6% | — |
| CVE-2013-7393 | LOW 2.4 | apache subversion The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4 | 0.6% | — |
| CVE-2026-68779 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-68776 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-67648 | MED 6.5 | microsoft sql_server_2017 Use of uninitialized resource in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-67645 | MED 6.5 | microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-47612 | HIGH 7.5 | nvidia dynamo NVIDIA Dynamo for Linux contains a vulnerability in the image loading component where an attacker may cause improper limitation of a pathname to a restricted directory. A successful exploit of this vulnerability might lead to information disclosure. | 0.6% | — |
| CVE-2026-49159 | MED 6.5 | microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. | 0.6% | — |
| CVE-2026-64125 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX path on GENET hardware once MAC EEE becomes active. RX traffic stops flowing while | 0.6% | — |
| CVE-2026-64089 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is never intended to hold a negative value. When a value greater than | 0.6% | — |
| CVE-2026-64056 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races b | 0.6% | — |
| CVE-2026-48206 | MED 5.3 | apache camel Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel JIRA component. The camel-jira producers read their operation parameters - the issue key, project key, transition id, summary, type, assignee, components | 0.6% | — |
| CVE-2026-46453 | MED 5.3 | apache camel Improper Input Validation, Authorization Bypass Through User-Controlled Key vulnerability in Apache Camel ElasticSearch Rest Client. The camel-elasticsearch-rest-client component reads several Exchange headers to control its behaviour - SEARCH_QUERY (an advan | 0.6% | — |