58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-4072 | MED 4.3 | cisco unified_computing_system The KVM subsystem in Cisco Unified Computing System (UCS) relies on a hardcoded X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers, and read keyboard and mouse events, by leveraging knowledge of this certificate's private key, aka | 0.6% | — |
| CVE-2026-66908 | HIGH 7.5 | apache camel Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authentication, configured through authe | 0.6% | — |
| CVE-2025-59282 | HIGH 7.0 | microsoft windows_10_1507 Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21184 | HIGH 7.0 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.6% | — |
| CVE-2024-56662 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: acpi: nfit: vmalloc-out-of-bounds Read in acpi_nfit_ctl Fix an issue detected by syzbot with KASAN: BUG: KASAN: vmalloc-out-of-bounds in cmd_to_func drivers/acpi/nfit/ core.c:416 [inline] B | 0.6% | — |
| CVE-2024-38086 | MED 6.4 | microsoft azure_kinect_software_development_kit Azure Kinect SDK Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-36719 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Speech Application Programming Interface (SAPI) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-36408 | HIGH 7.8 | microsoft windows_10_1607 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-23482 | MED 5.4 | ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim | 0.6% | — |
| CVE-2023-22637 | MED 6.5 | fortinet fortinac An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8 all versions, 8.7 all versions in License Mana | 0.6% | — |
| CVE-2022-44710 | HIGH 7.8 | microsoft windows_11 DirectX Graphics Kernel Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-42432 | MED 4.4 | linux linux_kernel This vulnerability allows local attackers to disclose sensitive information on affected installations of the Linux Kernel 6.0-rc2. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerabi | 0.6% | — |
| CVE-2022-28874 | MED 4.3 | f-secure atlant Multiple Denial-of-Service vulnerabilities was discovered in the F-Secure Atlant and in certain WithSecure products while scanning fuzzed PE32-bit files cause memory corruption and heap buffer overflow which eventually can crash the scanning engine. The exploi | 0.6% | — |
| CVE-2022-23766 | HIGH 7.8 | bigfile bigfileagent An improper input validation vulnerability leading to arbitrary file execution was discovered in BigFileAgent. In order to cause arbitrary files to be executed, the attacker makes the victim access a web page d by them or inserts a script using XSS into a gene | 0.6% | — |
| CVE-2021-43064 | MED 4.3 | fortinet fortiweb A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to use the device as a proxy and reach external or protected hosts via redirection handlers. | 0.6% | — |
| CVE-2021-3444 | HIGH 7.8 | canonical ubuntu_linux The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leadi | 0.6% | — |
| CVE-2020-3207 | MED 6.7 | cisco ios_xe A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticated, local attacker with root shell access to the underlying operating system (OS) to conduct a command injection attack during device boot. T | 0.6% | — |
| CVE-2026-65113 | CRIT 9.8 | nvidia infra_controller NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and informati | 0.6% | — |
| CVE-2026-59309 | CRIT 9.8 | vmware vcenter_server VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system. | 0.6% | — |
| CVE-2026-29226 | HIGH 7.3 | apache ofbiz Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue. | 0.6% | — |
| CVE-2025-59390 | CRIT 9.8 | apache druid Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`, which is not a crypto-gr | 0.6% | — |
| CVE-2025-47979 | MED 5.5 | microsoft windows_server_2022_23h2 Insertion of sensitive information into log file in Windows Failover Cluster allows an authorized attacker to disclose information locally. | 0.6% | — |
| CVE-2024-45720 | HIGH 8.2 | apache subversion On Windows platforms, a "best fit" character encoding conversion of command line arguments to Subversion's executables (e.g., svn.exe, etc.) may lead to unexpected command line argument interpretation, including argument injection and execution of other progra | 0.6% | — |
| CVE-2024-28919 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-20669 | MED 6.7 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |