58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36562 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-35348 | MED 6.5 | microsoft windows_server_2016 Active Directory Federation Service Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2021-34691 | HIGH 7.5 | idrive remotepc iDrive RemotePC before 4.0.1 on Linux allows denial of service. A remote and unauthenticated attacker can disconnect a valid user session by connecting to an ephemeral port. | 1.0% | — |
| CVE-2018-5510 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers. | 1.0% | — |
| CVE-2017-10608 | HIGH 7.5 | juniper junos Any Juniper Networks SRX series device with one or more ALGs enabled may experience a flowd crash when traffic is processed by the Sun/MS-RPC ALGs. This vulnerability in the Sun/MS-RPC ALG services component of Junos OS allows an attacker to cause a repeated d | 1.0% | — |
| CVE-2017-10607 | HIGH 7.5 | juniper junos Juniper Networks Junos OS 16.1R1, and services releases based off of 16.1R1, are vulnerable to the receipt of a crafted BGP Protocol Data Unit (PDU) sent directly to the router, which can cause the RPD routing process to crash and restart. Unlike BGP UPDATEs, | 1.0% | — |
| CVE-2026-40022 | HIGH 8.2 | apache camel When authentication is enabled on the Apache Camel embedded HTTP server or embedded management server (camel-platform-http-main) and a non-root context path such as /api or /admin is configured via camel.server.path or camel.management.path, the BasicAuthentic | 1.0% | — |
| CVE-2023-38741 | HIGH 7.5 | ibm txseries_for_multiplatform IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to | 1.0% | — |
| CVE-2023-36881 | MED 4.5 | microsoft azure_hdinsight Azure Apache Ambari Spoofing Vulnerability | 1.0% | — |
| CVE-2023-36877 | MED 4.5 | microsoft azure_hdinsight Azure Apache Oozie Spoofing Vulnerability | 1.0% | — |
| CVE-2022-22183 | HIGH 7.5 | juniper junos_os_evolved An Improper Access Control vulnerability in Juniper Networks Junos OS Evolved allows a network-based unauthenticated attacker who is able to connect to a specific open IPv4 port, which in affected releases should otherwise be unreachable, to cause the CPU to c | 1.0% | — |
| CVE-2022-20923 | MED 4.0 | cisco rv110w_firmware A vulnerability in the IPSec VPN Server authentication functionality of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an unauthenticated, remote attacker to bypass authentication controls and access the IPSec VPN network. This vuln | 1.0% | — |
| CVE-2020-2050 | HIGH 8.2 | paloaltonetworks pan-os An authentication bypass vulnerability exists in the GlobalProtect SSL VPN component of Palo Alto Networks PAN-OS software that allows an attacker to bypass all client certificate checks with an invalid certificate. A remote attacker can successfully authentic | 1.0% | — |
| CVE-2020-19725 | HIGH 7.8 | microsoft z3 There is a use-after-free vulnerability in file pdd_simplifier.cpp in Z3 before 4.8.8. It occurs when the solver attempt to simplify the constraints and causes unexpected memory access. It can cause segmentation faults or arbitrary code execution. | 1.0% | — |
| CVE-2020-0911 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows Modules Installer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context.</p> <p>An attacker could exploit t | 1.0% | — |
| CVE-2016-8478 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc | 1.0% | — |
| CVE-2016-8416 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produc | 1.0% | — |
| CVE-2014-3399 | MED 5.5 | cisco adaptive_security_appliance_software The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cach | 1.0% | — |
| CVE-2013-3888 | HIGH 8.4 | microsoft windows_7 dxgkrnl.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability." | 1.0% | — |
| CVE-2009-4804 | MED 4.3 | mario_matzulla calendar_base Cross-site scripting (XSS) vulnerability in the Calendar Base (cal) extension before 1.1.1 for TYPO3, when Internet Explorer 6 is used, allows remote attackers to inject arbitrary web script or HTML via "search parameters." | 1.0% | — |
| CVE-2008-6096 | MED 4.3 | juniper netscreen_screenos Cross-site scripting (XSS) vulnerability in Juniper NetScreen ScreenOS before 5.4r10, 6.0r6, and 6.1r2 allows remote attackers to inject arbitrary web script or HTML via the user name parameter to the (1) web interface login page or the (2) telnet login page. | 1.0% | — |
| CVE-2008-1503 | MED 4.3 | f5 tmos Cross-site scripting (XSS) vulnerability in the web management interface in F5 BIG-IP 9.4.3 allows remote attackers to inject arbitrary web script or HTML via (1) the name of a node object, or the (2) sysContact or (3) sysLocation SNMP configuration field, aka | 1.0% | — |
| CVE-2025-64678 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29956 | MED 5.4 | microsoft windows_10_1507 Buffer over-read in Windows SMB allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2023-49920 | MED 6.5 | apache airflow Apache Airflow, version 2.7.0 through 2.7.3, has a vulnerability that allows an attacker to trigger a DAG in a GET request without CSRF validation. As a result, it was possible for a malicious website opened in the same browser - by the user who also had Airfl | 1.0% | — |