58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-43407 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() This patch fixes an out-of-bounds access in ceph_handle_auth_reply() that can be triggered by a message of type CEPH_M | 0.5% | — |
| CVE-2025-62233 | MED 6.3 | apache dolphinscheduler Deserialization of Untrusted Data vulnerability in Apache DolphinScheduler RPC module. This issue affects Apache DolphinScheduler: Version >= 3.2.0 and < 3.3.1. Attackers who can access the Master or Worker nodes can compromise the system by creating a Sta | 0.5% | — |
| CVE-2024-52961 | HIGH 8.8 | fortinet fortisandbox An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2.1 through 4.2.7, FortiSandbox 4.0.0 through 4.0.5, FortiSandbox 3.2 all | 0.5% | — |
| CVE-2023-35020 | MED 5.4 | ibm sterling_control_center IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874. | 0.5% | — |
| CVE-2021-3039 | LOW 3.8 | paloaltonetworks prisma_cloud An information exposure through log file vulnerability exists in the Palo Alto Networks Prisma Cloud Compute Console where a secret used to authorize the role of the authenticated user is logged to a debug log file. Authenticated Operator role and Auditor role | 0.5% | — |
| CVE-2016-9795 | HIGH 7.8 | broadcom ca_workload_automation_ae The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and 5.9; CA Systems Performance for Infrastructure Managers 12.8 and 12.9; CA Universal Job Management Agent 11.2; CA Virtual Assurance for Infr | 0.5% | — |
| CVE-2015-8966 | HIGH 7.8 | linux linux_kernel arch/arm/kernel/sys_oabi-compat.c in the Linux kernel before 4.4 allows local users to gain privileges via a crafted (1) F_OFD_GETLK, (2) F_OFD_SETLK, or (3) F_OFD_SETLKW command in an fcntl64 system call. | 0.5% | — |
| CVE-2015-7600 | HIGH 7.2 | cisco vpn_client Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section. | 0.5% | — |
| CVE-2015-6303 | MED 4.3 | cisco spark The Cisco Spark application 2015-07-04 for mobile operating systems does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate, aka Bug IDs | 0.5% | — |
| CVE-2026-73180 | MED 6.8 | apache tomcat Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not b | 0.5% | — |
| CVE-2026-47476 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | 0.5% | — |
| CVE-2026-42975 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Bluetooth Port Driver allows an unauthorized attacker to execute code over an adjacent network. | 0.5% | — |
| CVE-2026-52982 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit() syzbot reported a KASAN slab-use-after-free read in rtl8150_start_xmit() when accessing skb->len for tx statistics after usb_sub | 0.5% | — |
| CVE-2026-26143 | HIGH 7.8 | microsoft powershell Improper input validation in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally. | 0.5% | — |
| CVE-2025-23323 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where a user could cause an integer overflow or wraparound, leading to a segmentation fault, by providing an invalid request. A successful exploit of this vulnerability might lead to | 0.5% | — |
| CVE-2025-25250 | MED 4.3 | fortinet fortios An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiSASE 25.1.c may allow | 0.5% | — |
| CVE-2024-47682 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: sd: Fix off-by-one error in sd_read_block_characteristics() Ff the device returns page 0xb1 with length 8 (happens with qemu v2.x, for example), sd_read_block_characteristics() may att | 0.5% | — |
| CVE-2024-45731 | HIGH 8.0 | splunk splunk In Splunk Enterprise for Windows versions below 9.3.1, 9.2.3, and 9.1.6, a low-privileged user that does not hold the "admin" or "power" Splunk roles could write a file to the Windows system root directory, which has a default location in the Windows System32 | 0.5% | — |
| CVE-2022-1901 | MED 5.3 | octopus octopus_server In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview. | 0.5% | — |
| CVE-2022-33670 | HIGH 7.8 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-22202 | MED 6.5 | juniper junos An Improper Handling of Exceptional Conditions vulnerability on specific PTX Series devices, including the PTX1000, PTX3000 (NextGen), PTX5000, PTX10002-60C, PTX10008, and PTX10016 Series, in Juniper Networks Junos OS allows an unauthenticated MPLS-based attac | 0.5% | — |
| CVE-2021-4197 | HIGH 7.8 | broadcom brocade_fabric_operating_system_firmware An unprivileged write to the file handler flaw in the Linux kernel's control groups and namespaces subsystem was found in the way users have access to some less privileged process that are controlled by cgroups and have higher privileged parent process. It is | 0.5% | — |
| CVE-2020-36386 | HIGH 7.1 | linux linux_kernel An issue was discovered in the Linux kernel before 5.8.1. net/bluetooth/hci_event.c has a slab out-of-bounds read in hci_extended_inquiry_result_evt, aka CID-51c19bf3d5cf. | 0.5% | — |
| CVE-2020-3135 | HIGH 8.8 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insuffi | 0.5% | — |
| CVE-2017-12313 | MED 6.7 | cisco packet_tracer An untrusted search path (aka DLL Preload) vulnerability in the Cisco Network Academy Packet Tracer software could allow an authenticated, local attacker to execute arbitrary code via DLL hijacking if a local user with administrative privileges executes the in | 0.5% | — |