58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-47408 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: check smcd_v2_ext_offset when receiving proposal msg When receiving proposal msg in server, the field smcd_v2_ext_offset in proposal msg is from the remote client and can not be ful | 0.6% | — |
| CVE-2024-27018 | HIGH 8.2 | fedoraproject fedora In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip conntrack input hook for promisc packets For historical reasons, when bridge device is in promisc mode, packets that are directed to the taps follow bridge inpu | 0.6% | — |
| CVE-2024-21315 | HIGH 7.8 | microsoft defender_for_endpoint Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-52290 | HIGH 8.1 | apache streampark In streampark-console the list pages(e.g: application pages), users can sort page by field. This sort field is sent from the front-end to the back-end, and the SQL query is generated using this field. However, because this sort field isn't validated, there is | 0.6% | — |
| CVE-2023-20223 | HIGH 8.6 | cisco dna_center A vulnerability in Cisco DNA Center could allow an unauthenticated, remote attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control enforcement on AP | 0.6% | — |
| CVE-2022-27516 | MED 5.3 | citrix application_delivery_controller_firmware User login brute force protection functionality bypass | 0.6% | — |
| CVE-2021-47130 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvmet: fix freeing unallocated p2pmem In case p2p device was found but the p2p pool is empty, the nvme target is still trying to free the sgl from the p2p pool instead of the regular sgl poo | 0.6% | — |
| CVE-2021-1270 | MED 6.3 | cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabili | 0.6% | — |
| CVE-2021-0222 | HIGH 7.4 | juniper junos A vulnerability in Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the device by sending certain crafted protocol packets from an adjacent device with invalid payloads to the device. These crafted packets, which should be dis | 0.6% | — |
| CVE-2020-3390 | HIGH 7.4 | cisco ios_xe A vulnerability in Simple Network Management Protocol (SNMP) trap generation for wireless clients of the Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause the device to unexp | 0.6% | — |
| CVE-2018-12896 | MED 5.5 | canonical ubuntu_linux An issue was discovered in the Linux kernel through 4.17.3. An Integer Overflow in kernel/time/posix-timers.c in the POSIX timer code is caused by the way the overrun accounting works. Depending on interval and expiry time values, the overrun can be larger tha | 0.6% | — |
| CVE-2017-1000363 | HIGH 7.8 | debian debian_linux Linux drivers/char/lp.c Out-of-Bounds Write. Due to a missing bounds check, and the fact that parport_ptr integer is static, a 'secure boot' kernel command line adversary (can happen due to bootloader vulns, e.g. Google Nexus 6's CVE-2016-10277, where due to a | 0.6% | — |
| CVE-2017-0465 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm ADSPRPC driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged proces | 0.6% | — |
| CVE-2016-6259 | MED 6.2 | citrix xenserver Xen 4.5.x through 4.7.x do not implement Supervisor Mode Access Prevention (SMAP) whitelisting in 32-bit exception and event delivery, which allows local 32-bit PV guest OS kernels to cause a denial of service (hypervisor and VM crash) by triggering a safety c | 0.6% | — |
| CVE-2025-53744 | HIGH 7.2 | fortinet fortios An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.0 all versions, 6.4 all versions, may allow a remote authenticated attacker with high privileges to escal | 0.6% | — |
| CVE-2025-32721 | HIGH 7.3 | microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2025-27427 | MED 4.3 | apache artemis A vulnerability exists in Apache ActiveMQ Artemis whereby a user with the createDurableQueue or createNonDurableQueue permission on an address can augment the routing-type supported by that address even if said user doesn't have the createAddress permission fo | 0.6% | — |
| CVE-2024-45479 | CRIT 9.1 | apache ranger SSRF vulnerability in Edit Service Page of Apache Ranger UI in Apache Ranger Version 2.4.0. Users are recommended to upgrade to version Apache Ranger 2.5.0, which fixes this issue. | 0.6% | — |
| CVE-2024-41177 | MED 6.1 | apache zeppelin Incomplete Blacklist to Cross-Site Scripting vulnerability in Apache Zeppelin. This issue affects Apache Zeppelin: before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. | 0.6% | — |
| CVE-2024-26246 | LOW 3.9 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-23663 | HIGH 8.8 | fortinet fortiextender_firmware An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an attacker to create users with elevated privileges via a crafted HTTP request. | 0.6% | — |
| CVE-2023-38173 | MED 4.3 | microsoft edge_chromium Microsoft Edge for Android Spoofing Vulnerability | 0.6% | — |
| CVE-2023-20095 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected d | 0.6% | — |
| CVE-2022-20725 | MED 5.5 | cisco cgr1000_compute_module Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 0.6% | — |
| CVE-2021-32584 | MED 5.3 | fortinet fortiwlc An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain ar | 0.6% | — |