58.165 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-5472 | MED 4.0 | linux linux_kernel The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry. | 0.5% | — |
| CVE-2014-5471 | MED 4.0 | linux linux_kernel Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 ima | 0.5% | — |
| CVE-2012-3510 | MED 5.6 | linux linux_kernel Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKST | 0.5% | — |
| CVE-2003-1428 | MED 4.8 | bharat_mediratta gallery Gallery 1.3.3 creates directories with insecure permissions, which allows local users to read, modify, or delete photos. | 0.5% | — |
| CVE-2026-78462 | HIGH 8.8 | microsoft visual_studio_code Authorization bypass through user-controlled key in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.5% | — |
| CVE-2026-57990 | HIGH 7.4 | microsoft edge_chromium Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2026-63795 | CRIT 10.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: 9p: avoid putting oldfid in p9_client_walk() error path When p9_client_walk() is called with clone set to false, fid aliases oldfid. If the walk subsequently fails after the request has been | 0.5% | — |
| CVE-2026-20190 | HIGH 7.5 | cisco identity_services_engine A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit t | 0.5% | — |
| CVE-2026-44631 | CRIT 9.8 | apache http_server Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the issue. | 0.5% | — |
| CVE-2026-5865 | HIGH 8.8 | google chrome Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2026-4673 | HIGH 8.8 | google chrome Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) | 0.5% | — |
| CVE-2024-52962 | MED 5.3 | fortinet fortianalyzer An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below, version 7.0.13 and below and FortiManager version 7.6.1 and below, version 7.4.5 and below, version 7 | 0.5% | — |
| CVE-2023-36635 | HIGH 7.1 | fortinet fortiswitchmanager An improper access control in Fortinet FortiSwitchManager version 7.2.0 through 7.2.2 7.0.0 through 7.0.1 may allow a remote authenticated read-only user to modify the interface settings via the API. | 0.5% | — |
| CVE-2023-35341 | MED 6.2 | microsoft windows_10_1507 Microsoft DirectMusic Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-23511 | HIGH 7.1 | amazon cloudwatch_agent A privilege escalation issue exists within the Amazon CloudWatch Agent for Windows, software for collecting metrics and logs from Amazon EC2 instances and on-premises servers, in versions up to and including v1.247354. When users trigger a repair of the Agent, | 0.5% | — |
| CVE-2022-20932 | MED 4.8 | cisco secure_firewall_management_center Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affecte | 0.5% | — |
| CVE-2022-20852 | MED 5.4 | cisco webex_meetings Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote attacker to conduct a cross-site scripting (XSS) attack or a frame hijacking attack against a user of the web interface. For more information about these vulnerabilities | 0.5% | — |
| CVE-2021-20544 | MED 4.3 | ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating o | 0.5% | — |
| CVE-2021-20421 | MED 4.3 | ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating o | 0.5% | — |
| CVE-2022-24489 | HIGH 7.8 | microsoft windows_server_2016 Cluster Client Failover (CCF) Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-1055 | HIGH 7.8 | canonical ubuntu_linux A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5 | 0.5% | — |
| CVE-2021-33110 | MED 6.5 | intel ac_1550_firmware Improper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 and 11 before version 22.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | 0.5% | — |
| CVE-2021-0296 | HIGH 7.4 | juniper ctpview The Juniper Networks CTPView server is not enforcing HTTP Strict Transport Security (HSTS). HSTS is an optional response header which allows servers to indicate that content from the requested domain will only be served over HTTPS. The lack of HSTS may leave t | 0.5% | — |
| CVE-2021-24016 | LOW 3.7 | fortinet fortimanager An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely | 0.5% | — |
| CVE-2020-1689 | MED 6.5 | juniper junos On Juniper Networks EX4300-MP Series, EX4600 Series and QFX5K Series deployed in a Virtual Chassis configuration, receipt of a stream of specific layer 2 frames can cause high CPU load, which could lead to traffic interruption. This issue does not occur when t | 0.5% | — |