58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-47150 | HIGH 7.5 | ibm common_cryptographic_architecture IBM Common Cryptographic Architecture (CCA) 7.0.0 through 7.5.36 could allow a remote user to cause a denial of service due to incorrect data handling for certain types of AES operations. IBM X-Force ID: 270602. | 0.6% | — |
| CVE-2021-47368 | HIGH 7.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: enetc: Fix illegal access when reading affinity_hint irq_set_affinity_hit() stores a reference to the cpumask_t parameter in the irq descriptor, and that reference can be accessed later from | 0.6% | — |
| CVE-2021-45231 | HIGH 7.8 | trendmicro apex_one A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which cou | 0.6% | — |
| CVE-2021-34493 | MED 6.7 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-15917 | HIGH 7.0 | debian debian_linux An issue was discovered in the Linux kernel before 5.0.5. There is a use-after-free issue when hci_uart_register_dev() fails in hci_uart_set_proto() in drivers/bluetooth/hci_ldisc.c. | 0.6% | — |
| CVE-2015-0239 | MED 4.4 | canonical ubuntu_linux The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of a 16 | 0.6% | — |
| CVE-2014-8031 | MED 6.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456. | 0.6% | — |
| CVE-2014-7996 | MED 6.8 | cisco unified_computing_system Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Integrated Management Controller in Cisco Unified Computing System allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuq45477. | 0.6% | — |
| CVE-2012-3908 | MED 6.8 | cisco identity_services_engine Multiple cross-site request forgery (CSRF) vulnerabilities in the ISE Administrator user interface (aka the Apache Tomcat interface) on Cisco Identity Services Engine (ISE) 3300 series appliances before 1.1.0.665 Cumulative Patch 1 allow remote attackers to hi | 0.6% | — |
| CVE-2026-69375 | MED 6.5 | microsoft exchange_server Authorization bypass through user-controlled key in Microsoft Exchange Server allows an authorized attacker to perform tampering over a network. | 0.6% | — |
| CVE-2026-63042 | HIGH 8.1 | apache inlong Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify and delete Data Node definitions. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Users are advis | 0.6% | — |
| CVE-2026-63040 | HIGH 8.1 | apache inlong Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated user can logically delete ALL stream sources. This issue affects Apache InLong: from 2.0.0 before 2.4.0. Use | 0.6% | — |
| CVE-2026-62915 | MED 6.5 | microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2026-58279 | MED 6.5 | microsoft azure_cyclecloud Missing authorization in Azure CycleCloud allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-42830 | MED 6.5 | microsoft azure_monitor_agent Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.6% | — |
| CVE-2026-35422 | MED 6.5 | microsoft windows_10_1607 Authentication bypass using an alternate path or channel in Windows TCP/IP allows an authorized attacker to bypass a security feature over a network. | 0.6% | — |
| CVE-2025-59489 | HIGH 7.4 | unity editor Unity Runtime before 2025-10-02 on Android, Windows, macOS, and Linux allows argument injection that can result in loading of library code from an unintended location. If an application was built with a version of Unity Editor that had the vulnerable Unity Run | 0.6% | — |
| CVE-2025-47995 | MED 6.5 | microsoft azure_machine_learning Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2024-53167 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nfs/blocklayout: Don't attempt unregister for invalid block device Since commit d869da91cccb ("nfs/blocklayout: Fix premature PR key unregistration") an unmount of a pNFS SCSI layout-enabled | 0.6% | — |
| CVE-2024-36476 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move the declaration of the 'ib_sge list' variable outside the 'always_invalidate' block to ensure it remains accessible for use throughout the | 0.6% | — |
| CVE-2024-27181 | HIGH 8.8 | apache linkis In Apache Linkis <= 1.5.0, Privilege Escalation in Basic management services where the attacking user is a trusted account allows access to Linkis's Token information. Users are advised to upgrade to version 1.6.0, which fixes this issue. | 0.6% | — |
| CVE-2024-26626 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipmr: fix kernel panic when forwarding mcast packets The stacktrace was: [ 86.305548] BUG: kernel NULL pointer dereference, address: 0000000000000092 [ 86.306815] #PF: supervisor read ac | 0.6% | — |
| CVE-2024-20268 | HIGH 7.7 | cisco adaptive_security_appliance_software A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause an unexpected reload of the de | 0.6% | — |
| CVE-2023-52610 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: fix skb leak and crash on ooo frags act_ct adds skb->users before defragmentation. If frags arrive in order, the last frag's reference is reset in: inet_frag_reasm_prep | 0.6% | — |
| CVE-2023-32041 | MED 5.5 | microsoft windows_10_1607 Windows Update Orchestrator Service Information Disclosure Vulnerability | 0.6% | — |