58.628 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.628 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2013-6763 | MED 6.9 | linux linux_kernel The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, | 0.6% | — |
| CVE-2026-63016 | MED 5.3 | apache inlong Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packages. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advised to upgrade to Apache InLon | 0.6% | — |
| CVE-2026-2749 | CRIT 9.9 | centreon open_tickets Vulnerability in Centreon Centreon Open Tickets on Central Server on Linux (Centroen Open Ticket modules).This issue affects Centreon Open Tickets on Central Server: from all before 25.10.3, 24.10.8, 24.04.7. | 0.6% | — |
| CVE-2025-59294 | LOW 2.1 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Taskbar Live allows an unauthorized attacker to disclose information with a physical attack. | 0.6% | — |
| CVE-2024-43508 | MED 5.5 | microsoft windows_11_22h2 Windows Graphics Component Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-43500 | MED 5.5 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Information Disclosure Vulnerability | 0.6% | — |
| CVE-2022-23257 | HIGH 8.8 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-22050 | HIGH 7.8 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21862 | HIGH 7.0 | microsoft windows_10 Windows Application Model Core API Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-21859 | HIGH 7.0 | microsoft windows_10 Windows Accounts Control Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-3043 | HIGH 7.5 | paloaltonetworks prisma_cloud A reflected cross-site scripting (XSS) vulnerability exists in the Prisma Cloud Compute web console that enables a remote attacker to execute arbitrary JavaScript code in the browser-based web console while an authenticated administrator is using that web inte | 0.6% | — |
| CVE-2019-1893 | HIGH 7.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. The vulnerability is due to insufficient i | 0.6% | — |
| CVE-2026-58624 | MED 5.4 | apache mina_sshd Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.apache.sshd:sshd-git provides though its GitPgmCommandFactory a way to configure an Apache MINA SSHD server suc | 0.6% | — |
| CVE-2026-39999 | CRIT 9.1 | apache apisix Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin. This issue affects Apache APISIX: from v2.2 through v3.16.0. Users are recommended | 0.6% | — |
| CVE-2026-24013 | CRIT 9.1 | apache iotdb Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter. An attacker can construct requests with a forged sessionId and, without performing openSession authentication, | 0.6% | — |
| CVE-2025-59494 | HIGH 7.8 | microsoft azure_monitor_agent Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2024-45001 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix RX buf alloc_size alignment and atomic op panic The MANA driver's RX buffer alloc_size is passed into napi_build_skb() to create SKB. skb_shinfo(skb) is located at the end of | 0.6% | — |
| CVE-2024-20484 | HIGH 7.5 | cisco enterprise_chat_and_email A vulnerability in the External Agent Assignment Service (EAAS) feature of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to | 0.6% | — |
| CVE-2023-43767 | HIGH 7.5 | f-secure atlant Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, | 0.6% | — |
| CVE-2023-43765 | HIGH 7.5 | f-secure atlant Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Cli | 0.6% | — |
| CVE-2023-43761 | HIGH 7.5 | f-secure atlant Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Sec | 0.6% | — |
| CVE-2023-43760 | HIGH 7.5 | f-secure atlant Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Cli | 0.6% | — |
| CVE-2023-25738 | MED 6.5 | mozilla firefox Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects | 0.6% | — |
| CVE-2023-22399 | HIGH 7.5 | juniper junos When sFlow is enabled and it monitors a packet forwarded via ECMP, a buffer management vulnerability in the dcpfe process of Juniper Networks Junos OS on QFX10K Series systems allows an attacker to cause the Packet Forwarding Engine (PFE) to crash and restart | 0.6% | — |
| CVE-2023-0459 | MED 6.5 | linux linux_kernel Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend up | 0.6% | — |