58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-50498 | HIGH 7.8 | microsoft windows_10_1607 Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2025-13214 | HIGH 7.6 | ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | 0.4% | — |
| CVE-2025-23339 | LOW 3.3 | nvidia cuda_toolkit NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary | 0.4% | — |
| CVE-2025-52447 | HIGH 8.1 | tableau tableau_server Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Se | 0.4% | — |
| CVE-2025-48819 | HIGH 7.1 | microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network. | 0.4% | — |
| CVE-2025-30679 | MED 6.5 | trendmicro apex_central A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | 0.4% | — |
| CVE-2025-30678 | MED 6.5 | trendmicro apex_central A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | 0.4% | — |
| CVE-2025-27475 | HIGH 7.0 | microsoft windows_11_22h2 Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2024-45323 | MED 4.3 | fortinet fortiedrmanager An improper access control vulnerability [CWE-284] in FortiEDR Manager API 6.2.0 through 6.2.2, 6.0 all versions may allow in a shared environment context an authenticated admin with REST API permissions in his profile and restricted to a specific organization | 0.4% | — |
| CVE-2024-41840 | HIGH 7.8 | adobe bridge Bridge versions 13.0.8, 14.1.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a | 0.4% | — |
| CVE-2024-30389 | MED 5.8 | juniper junos An Incorrect Behavior Order vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on EX4300 Series allows an unauthenticated, network-based attacker to cause an integrity impact to networks downstream of the vulnerable device. When | 0.4% | — |
| CVE-2024-30410 | MED 5.8 | juniper junos An Incorrect Behavior Order in the routing engine (RE) of Juniper Networks Junos OS on EX4300 Series allows traffic intended to the device to reach the RE instead of being discarded when the discard term is set in loopback (lo0) interface. The intended functio | 0.4% | — |
| CVE-2023-36405 | HIGH 7.0 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-2873 | MED 5.3 | filseclab twister_antivirus A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component IoControlCode Handler. The manipulation leads to memory corr | 0.4% | — |
| CVE-2023-2006 | HIGH 7.0 | linux linux_kernel A race condition was found in the Linux kernel's RxRPC network protocol, within the processing of RxRPC bundles. This issue results from the lack of proper locking when performing operations on an object. This may allow an attacker to escalate privileges and e | 0.4% | — |
| CVE-2022-34009 | MED 5.5 | fossil-scm fossil Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS payload in a ticket. This occurs because the ticket data is stored in a temporary file, and the product does not properly handle the absence of this file after Windo | 0.4% | — |
| CVE-2022-22454 | HIGH 7.8 | ibm infosphere_information_server_on_cloud IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. | 0.4% | — |
| CVE-2021-27194 | HIGH 8.8 | netop vision_pro Cleartext transmission of sensitive information in Netop Vision Pro up to and including 9.7.1 allows a remote unauthenticated attacker to gather credentials including Windows login usernames and passwords. | 0.4% | — |
| CVE-2020-26155 | HIGH 7.8 | utimaco block-safe_firmware Multiple files and folders in Utimaco SecurityServer 4.20.0.4 and 4.31.1.0. are installed with Read/Write permissions for authenticated users, which allows for binaries to be manipulated by non-administrator users. Additionally, entries are made to the PATH en | 0.4% | — |
| CVE-2020-1618 | MED 6.3 | juniper junos On Juniper Networks EX and QFX Series, an authentication bypass vulnerability may allow a user connected to the console port to login as root without any password. This issue might only occur in certain scenarios: • At the first reboot after performing device | 0.4% | — |
| CVE-2017-18595 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 4.14.11. A double free may be caused by the function allocate_trace_buffer in the file kernel/trace/trace.c. | 0.4% | — |
| CVE-2019-1966 | HIGH 7.8 | cisco nx-os A vulnerability in a specific CLI command within the local management (local-mgmt) context for Cisco UCS Fabric Interconnect Software could allow an authenticated, local attacker to gain elevated privileges as the root user on an affected device. The vulnerabi | 0.4% | — |
| CVE-2019-1592 | HIGH 7.8 | cisco nx-os A vulnerability in the background operations functionality of Cisco Nexus 9000 Series Application Centric Infrastructure (ACI) Mode Switch Software could allow an authenticated, local attacker to gain elevated privileges as root on an affected device. The vuln | 0.4% | — |
| CVE-2017-10624 | HIGH 7.5 | juniper junos_space Insufficient verification of node certificates in Juniper Networks Junos Space may allow a man-in-the-middle type of attacker to make unauthorized modifications to Space database or add nodes. Affected releases are Juniper Networks Junos Space all versions pri | 0.4% | — |
| CVE-2017-2329 | MED 6.2 | juniper northstar_controller An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing wide | 0.4% | — |