58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-20543 | MED 5.4 | ibm jazz_team_server IBM Jazz Team Server 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IB | 0.6% | — |
| CVE-2019-13401 | HIGH 8.8 | fortinet fcm-mb40_firmware Dynacolor FCM-MB40 v1.2.0.0 devices have CSRF in all scripts under cgi-bin/. | 0.6% | — |
| CVE-2018-3990 | CRIT 9.3 | wibu wibukey An exploitable pool corruption vulnerability exists in the 0x8200E804 IOCTL handler functionality of WIBU-SYSTEMS WibuKey.sys Version 6.40 (Build 2400). A specially crafted IRP request can cause a buffer overflow, resulting in kernel memory corruption and, pot | 0.6% | — |
| CVE-2016-5236 | MED 5.4 | f5 websafe_alert_server Cross-Site-Scripting (XSS) vulnerabilities in F5 WebSafe Dashboard 3.9.5 and earlier, aka F5 WebSafe Alert Server, allow privileged authenticated users to inject arbitrary web script or HTML when creating a new user, account or signature. | 0.6% | — |
| CVE-2015-0651 | MED 6.8 | cisco application_networking_manager Cross-site request forgery (CSRF) vulnerability in the web GUI in Cisco Application Networking Manager (ANM), and Device Manager (DM) on Cisco 4710 Application Control Engine (ACE) appliances, allows remote attackers to hijack the authentication of arbitrary u | 0.6% | — |
| CVE-2013-1128 | MED 6.8 | cisco unified_meetingplace Multiple cross-site request forgery (CSRF) vulnerabilities in the server in Cisco Unified MeetingPlace before 7.1(2.2000) allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuc64903. NOTE: some of thes | 0.6% | — |
| CVE-2026-75686 | CRIT 9.3 | adobe connect Adobe Connect is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue require | 0.6% | — |
| CVE-2026-66391 | MED 6.5 | apache wicket Use of Insufficiently Random Values, Protection Mechanism Failure vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, which fixes the is | 0.6% | — |
| CVE-2026-65945 | MED 6.5 | apache ranger Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.6% | — |
| CVE-2026-65675 | HIGH 7.1 | microsoft github_copilot_chat No cwe for this issue in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2026-50630 | MED 6.5 | apache cxf A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker ca | 0.6% | — |
| CVE-2026-34031 | MED 6.5 | apache answer Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile | 0.6% | — |
| CVE-2026-32175 | MED 4.3 | microsoft .net A tampering vulnerability exists when .NET Core improperly handles specially crafted files. An attacker who successfully exploited this vulnerability could write arbitrary files and directories to certain locations on a vulnerable system. However, an attacker | 0.6% | — |
| CVE-2026-28718 | HIGH 7.5 | acronis cyber_protect Denial of service due to insufficient input validation in authentication logging. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.6% | — |
| CVE-2025-62559 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-62558 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-53151 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: svcrdma: Address an integer overflow Dan Carpenter reports: > Commit 78147ca8b4a9 ("svcrdma: Add a "parsed chunk list" data > structure") from Jun 22, 2020 (linux-next), leads to the followi | 0.6% | — |
| CVE-2024-43554 | MED 5.5 | microsoft windows_10_1507 Windows Kernel-Mode Driver Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-43509 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-35916 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-buf: Fix NULL pointer dereference in sanitycheck() If due to a memory allocation failure mock_chain() returns NULL, it is passed to dma_fence_enable_sw_signaling() resulting in NULL poin | 0.6% | — |
| CVE-2024-30027 | HIGH 7.8 | microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-21431 | HIGH 7.8 | microsoft windows_10_21h2 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2023-20891 | MED 6.5 | vmware isolation_segment The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system | 0.6% | — |
| CVE-2021-29849 | MED 6.1 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 0.6% | — |
| CVE-2021-0244 | HIGH 7.4 | juniper junos A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS due to the absence of a specific protection mechanism to avoid a race condition which may allow an attacker to bypass the storm-control feature o | 0.6% | — |