58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-43950 | MED 4.3 | fortinet fortinac A URL redirection to untrusted site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.1 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions may allow an unauthenticated attacker to redi | 0.4% | — |
| CVE-2023-2282 | MED 6.5 | devolutions remote_desktop_manager Improper access control in the Web Login listener in Devolutions Remote Desktop Manager 2023.1.22 and earlier on Windows allows an authenticated user to bypass administrator-enforced Web Login restrictions and gain access to entries via an unexpected vector. | 0.4% | — |
| CVE-2023-21804 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2022-22237 | MED 6.5 | juniper junos An Improper Authentication vulnerability in the kernel of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause an impact on confidentiality or integrity. A vulnerability in the processing of TCP-AO will allow a BGP or LDP peer n | 0.4% | — |
| CVE-2021-26103 | MED 6.3 | fortinet fortios An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and below and FortiGate verison 7.0.0, 6.4.6 and below, 6.2.9 and below of SSL VPN portal may allow a remote, unauthen | 0.4% | — |
| CVE-2021-31370 | MED 6.5 | juniper junos An Incomplete List of Disallowed Inputs vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and EX4600 Series allows an adjacent unauthenticated attacker which sends a high rate of specific multicast traffic to cause | 0.4% | — |
| CVE-2021-31362 | MED 6.5 | juniper junos A Protection Mechanism Failure vulnerability in RPD (routing protocol daemon) of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent unauthenticated attacker to cause established IS-IS adjacencies to go down by sending a spoofed hello PDU leading | 0.4% | — |
| CVE-2021-36376 | HIGH 7.8 | delta_project delta dandavison delta before 0.8.3 on Windows resolves an executable's pathname as a relative path from the current directory. | 0.4% | — |
| CVE-2020-16119 | MED 6.3 | canonical ubuntu_linux Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4 | 0.4% | — |
| CVE-2020-36161 | HIGH 8.8 | veritas aptare_it_analytics An issue was discovered in Veritas APTARE 10.4 before 10.4P9 and 10.5 before 10.5P3. By default, on Windows systems, users can create directories under C:\. A low privileged user can create a directory at the configuration file locations. When the Windows syst | 0.4% | — |
| CVE-2020-15593 | HIGH 7.8 | riverbed steelcentral_aternity_agent SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes a | 0.4% | — |
| CVE-2019-19072 | MED 4.4 | canonical ubuntu_linux A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6. | 0.4% | — |
| CVE-2019-16231 | MED 4.1 | canonical ubuntu_linux drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. | 0.4% | — |
| CVE-2017-16534 | MED 6.8 | linux linux_kernel The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device. | 0.4% | — |
| CVE-2017-6768 | HIGH 7.8 | cisco application_policy_infrastructure_controller A vulnerability in the build procedure for certain executable system files installed at boot time on Cisco Application Policy Infrastructure Controller (APIC) devices could allow an authenticated, local attacker to gain root-level privileges. The vulnerability | 0.4% | — |
| CVE-2017-8925 | MED 5.5 | debian debian_linux The omninet_open function in drivers/usb/serial/omninet.c in the Linux kernel before 4.10.4 allows local users to cause a denial of service (tty exhaustion) by leveraging reference count mishandling. | 0.4% | — |
| CVE-2012-4141 | MED 6.2 | cisco nx-os Directory traversal vulnerability in the CLI parser in Cisco NX-OS allows local users to create arbitrary script files via a relative pathname in the "file name" parameter, aka Bug IDs CSCua71557 and CSCua71551. | 0.4% | — |
| CVE-2013-4300 | HIGH 7.2 | linux linux_kernel The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing. | 0.4% | — |
| CVE-2010-2954 | MED 4.9 | canonical ubuntu_linux The irda_bind function in net/irda/af_irda.c in the Linux kernel before 2.6.36-rc3-next-20100901 does not properly handle failure of the irda_open_tsap function, which allows local users to cause a denial of service (NULL pointer dereference and panic) and pos | 0.4% | — |
| CVE-2006-0555 | LOW 2.1 | linux linux_kernel The Linux Kernel before 2.6.15.5 allows local users to cause a denial of service (NFS client panic) via unknown attack vectors related to the use of O_DIRECT (direct I/O). | 0.4% | — |
| CVE-2005-3107 | LOW 2.1 | linux linux_kernel fs/exec.c in Linux 2.6, when one thread is tracing another thread that shares the same memory map, might allow local users to cause a denial of service (deadlock) by forcing a core dump when the traced thread is in the TASK_TRACED state. | 0.4% | — |
| CVE-2005-3053 | LOW 2.1 | linux linux_kernel The sys_set_mempolicy function in mempolicy.c in Linux kernel 2.6.x allows local users to cause a denial of service (kernel BUG()) via a negative first argument. | 0.4% | — |
| CVE-2005-3044 | LOW 2.1 | linux linux_kernel Multiple vulnerabilities in Linux kernel before 2.6.13.2 allow local users to cause a denial of service (kernel OOPS from null dereference) via (1) fput in a 32-bit ioctl on 64-bit x86 systems or (2) sockfd_put in the 32-bit routing_ioctl function on 64-bit sy | 0.4% | — |
| CVE-2026-71407 | MED 5.6 | fortinet fortios A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon vi | 0.4% | — |
| CVE-2026-70335 | HIGH 7.8 | microsoft visual_studio_code Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |