58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-47139 | MED 6.8 | f5 big-iq_centralized_management A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Software versio | 0.5% | — |
| CVE-2021-47587 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: systemport: Add global locking for descriptor lifecycle The descriptor list is a shared resource across all of the transmit queues, and the locking mechanism used today only protects co | 0.5% | — |
| CVE-2024-23669 | MED 6.5 | fortinet fortiwebmanager An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 through 6.2.4, FortiWebManager 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CL | 0.5% | — |
| CVE-2023-36843 | HIGH 7.5 | juniper junos An Improper Handling of Inconsistent Special Elements vulnerability in the Junos Services Framework (jsf) module of Juniper Networks Junos OS allows an unauthenticated network based attacker to cause a crash in the Packet Forwarding Engine (pfe) and thereby r | 0.5% | — |
| CVE-2023-38419 | MED 4.3 | f5 big-ip_access_policy_manager An authenticated attacker with guest privileges or higher can cause the iControl SOAP process to terminate by sending undisclosed requests. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.5% | — |
| CVE-2021-42083 | HIGH 8.7 | osnexus quantastor An authenticated attacker is able to create alerts that trigger a stored XSS attack. POC * go to the alert manager * open the ITSM tab * add a webhook with the URL/service token value ' -h && id | tee /tmp/ttttttddddssss #' (whitespaces are tab | 0.5% | — |
| CVE-2023-24934 | MED 6.2 | microsoft malware_protection_platform Microsoft Defender Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2022-41050 | HIGH 7.8 | microsoft windows_10 Windows Extensible File Allocation Table Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2017-7541 | HIGH 7.8 | linux linux_kernel The brcmf_cfg80211_mgmt_tx function in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux kernel before 4.12.3 allows local users to cause a denial of service (buffer overflow and system crash) or possibly gain privileges via a crafted NL | 0.5% | — |
| CVE-2013-4270 | LOW 3.6 | linux linux_kernel The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended /proc/sys/net restrictions via a crafted application. | 0.5% | — |
| CVE-2009-0056 | MED 6.8 | cisco ironport_encryption_appliance Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before | 0.5% | — |
| CVE-2026-62900 | MED 5.9 | microsoft .net Improper removal of sensitive information before storage or transfer in .NET allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-67305 | HIGH 8.8 | freerdp freerdp FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP | 0.5% | — |
| CVE-2024-53138 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: kTLS, Fix incorrect page refcounting The kTLS tx handling code is using a mix of get_page() and page_ref_inc() APIs to increment the page reference. But on the release path (mlx5e | 0.5% | — |
| CVE-2024-43644 | HIGH 7.8 | microsoft windows_10_1507 Windows Client-Side Caching Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2024-20278 | MED 6.5 | cisco ios_xe A vulnerability in the NETCONF feature of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exp | 0.5% | — |
| CVE-2024-1221 | LOW 3.1 | papercut papercut_mf This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a specifically formed payload against the impacted API endpoint. The attacker must carry out some reconnaissance to gain knowledge of a system token. This CVE only affec | 0.5% | — |
| CVE-2024-26583 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tls: fix race between async notify and socket close The submitting thread (one which called recvmsg/sendmsg) may exit as soon as the async crypto handler calls complete() so any code past th | 0.5% | — |
| CVE-2023-20271 | MED 6.5 | cisco evolved_programmable_network_manager A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability i | 0.5% | — |
| CVE-2023-32052 | MED 5.4 | microsoft power_apps Microsoft Power Apps (online) Spoofing Vulnerability | 0.5% | — |
| CVE-2022-41780 | MED 5.5 | f5 f5os-a In F5OS-A version 1.x before 1.1.0 and F5OS-C version 1.x before 1.4.0, a directory traversal vulnerability exists in an undisclosed location of the F5OS CLI that allows an attacker to read arbitrary files. | 0.5% | — |
| CVE-2022-23442 | MED 4.3 | fortinet fortios An improper access control vulnerability [CWE-284] in FortiOS versions 6.2.0 through 6.2.11, 6.4.0 through 6.4.8 and 7.0.0 through 7.0.5 may allow an authenticated attacker with a restricted user profile to gather the checksum information about the other VDOMs | 0.5% | — |
| CVE-2021-42285 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-0253 | HIGH 7.8 | juniper junos NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. This issue affects Juniper Networks Ju | 0.5% | — |
| CVE-2016-3138 | MED 4.6 | canonical ubuntu_linux The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint de | 0.5% | — |