58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-7339 | MED 6.1 | fortinet fortiportal A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality. | 0.7% | — |
| CVE-2016-1273 | MED 5.9 | juniper junos Juniper Junos OS before 13.2X51-D40, 14.x before 14.1X53-D30, and 15.x before 15.1X53-D20 on QFX5100 and QFX10002 switches do not have sufficient entropy, which makes it easier for remote attackers to defeat cryptographic encryption and authentication protecti | 0.7% | — |
| CVE-2026-57089 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows SMB Server Network Transport Driver (srvnet.sys) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-41870 | HIGH 8.8 | apache nutch Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Nutch Server ( | 0.7% | — |
| CVE-2026-14499 | HIGH 8.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component. | 0.7% | — |
| CVE-2025-59218 | CRIT 9.6 | microsoft entra_id Azure Entra ID Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-53804 | MED 5.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-53803 | MED 5.5 | microsoft windows_10_1507 Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally. | 0.7% | — |
| CVE-2024-52053 | CRIT 9.6 | wowza streaming_engine Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side JavaScript into the web dashboard to automatically hijack admin accounts. | 0.7% | — |
| CVE-2024-43641 | HIGH 7.8 | microsoft windows_10_1507 Windows Registry Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-6857 | MED 5.3 | debian debian_linux When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. *This bug only affects Firefox on Unix-based operating systems (Android, Linux, MacOS). Windows is unaffected.* This vulnerability affects | 0.7% | — |
| CVE-2022-48789 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-tcp: fix possible use-after-free in transport error_recovery work While nvme_tcp_submit_async_event_work is checking the ctrl and queue state before preparing the AER command and schedu | 0.7% | — |
| CVE-2019-3654 | MED 5.3 | mcafee client_proxy Authentication Bypass vulnerability in the Microsoft Windows client in McAfee Client Proxy (MCP) prior to 3.0.0 allows local user to bypass scanning of web traffic and gain access to blocked sites for a short period of time via generating an authorization key | 0.7% | — |
| CVE-2019-0046 | MED 6.5 | juniper junos A vulnerability in the pfe-chassisd Chassis Manager (CMLC) daemon of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) to the EX4300 when specific valid broadcast packets create a broadcast storm condition when received on the me0 | 0.7% | — |
| CVE-2017-7343 | MED 6.1 | fortinet fortiportal An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter. | 0.7% | — |
| CVE-2026-13448 | HIGH 8.1 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in the validate | 0.7% | — |
| CVE-2025-26865 | LOW 3.5 | apache ofbiz Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: from 18.12.17 before 18.12.18. It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which | 0.7% | — |
| CVE-2025-22219 | MED 6.8 | vmware aria_operations_for_logs VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-administrative privileges may be able to inject a malicious script that (can perform stored cross-site scripting) may lead to arbitrary operations | 0.7% | — |
| CVE-2024-57973 | HIGH 8.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rdma/cxgb4: Prevent potential integer overflow on 32bit The "gl->tot_len" variable is controlled by the user. It comes from process_responses(). On 32bit systems, the "gl->tot_len + sizeof | 0.7% | — |
| CVE-2022-23296 | HIGH 7.8 | microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-1421 | HIGH 7.8 | cisco enterprise_nfv_infrastructure_software A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to perform a command injection attack on an affected device. The vulnerability is due to insufficient validation of user-supplied input to a co | 0.7% | — |
| CVE-2020-3465 | HIGH 7.4 | cisco ios_xe A vulnerability in Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause a device to reload. The vulnerability is due to incorrect handling of certain valid, but not typical, Ethernet frames. An attacker could exploit this vulnerabil | 0.7% | — |
| CVE-2019-15291 | MED 4.6 | linux linux_kernel An issue was discovered in the Linux kernel through 5.2.9. There is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe function in the drivers/media/usb/b2c2/flexcop-usb.c driver. | 0.7% | — |
| CVE-2018-7492 | MED 5.5 | canonical ubuntu_linux A NULL pointer dereference was found in the net/rds/rdma.c __rds_rdma_map() function in the Linux kernel before 4.14.7 allowing local attackers to cause a system panic and a denial-of-service, related to RDS_GET_MR and RDS_GET_MR_FOR_DEST. | 0.7% | — |
| CVE-2016-1280 | MED 6.5 | juniper junos PKId in Juniper Junos OS before 12.1X44-D52, 12.1X46 before 12.1X46-D37, 12.1X47 before 12.1X47-D30, 12.3 before 12.3R12, 12.3X48 before 12.3X48-D20, 13.3 before 13.3R10, 14.1 before 14.1R8, 14.1X53 before 14.1X53-D40, 14.2 before 14.2R7, 15.1 before 15.1R4, 1 | 0.7% | — |