58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22329 | MED 4.3 | ibm control_desk IBM Control Desk 7.6.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent | 0.7% | — |
| CVE-2022-21871 | HIGH 7.0 | microsoft visual_studio_2017 Microsoft Diagnostics Hub Standard Collector Runtime Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-8428 | HIGH 7.1 | linux linux_kernel fs/namei.c in the Linux kernel before 5.5 has a may_create_in_sticky use-after-free, which allows local users to cause a denial of service (OOPS) or possibly obtain sensitive information from kernel memory, aka CID-d0cb50185ae9. One attack vector may be an ope | 0.7% | — |
| CVE-2019-15217 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver. | 0.7% | — |
| CVE-2017-12341 | MED 6.7 | cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. An attacker would need valid administrator credentials to perform this exploit. The vulnerability is due to insufficie | 0.7% | — |
| CVE-2013-0248 | MED 6.8 | apache commons_fileupload The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. | 0.7% | — |
| CVE-2012-4001 | MED 5.0 | google mod_pagespeed The mod_pagespeed module before 0.10.22.6 for the Apache HTTP Server does not properly verify its host name, which allows remote attackers to trigger HTTP requests to arbitrary hosts via unspecified vectors, as demonstrated by requests to intranet servers. | 0.7% | — |
| CVE-2026-61363 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-59134 | HIGH 7.5 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-40376 | HIGH 7.5 | microsoft visual_studio_code Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-57740 | HIGH 7.5 | fortinet fortios An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions; FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, 1.2 all versions | 0.7% | — |
| CVE-2024-56645 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: can: j1939: j1939_session_new(): fix skb reference counting Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() t | 0.7% | — |
| CVE-2024-38215 | HIGH 7.8 | microsoft windows_10_1809 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38135 | HIGH 7.8 | microsoft windows_11_22h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-38134 | HIGH 7.8 | microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2024-27439 | MED 6.5 | apache wicket An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not suppo | 0.7% | — |
| CVE-2023-35315 | HIGH 8.8 | microsoft windows_10_1809 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-28296 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-20042 | MED 6.8 | cisco adaptive_security_appliance_software A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected | 0.7% | — |
| CVE-2022-21967 | HIGH 7.0 | microsoft windows_10 Xbox Live Auth Manager for Windows Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-39063 | CRIT 9.1 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information due to a misconfiguration in access control headers. IBM X-Force ID: | 0.7% | — |
| CVE-2021-29773 | MED 5.4 | ibm security_guardium IBM Security Guardium 10.6 and 11.3 could allow a remote authenticated attacker to obtain sensitive information or modify user details caused by an insecure direct object vulnerability (IDOR). IBM X-Force ID: 202865. | 0.7% | — |
| CVE-2020-5905 | MED 4.3 | f5 big-ip_access_policy_manager In version 11.6.1-11.6.5.2 of the BIG-IP system Configuration utility Network > WCCP page, the system does not sanitize all user-provided data before display. | 0.7% | — |
| CVE-2020-3199 | HIGH 8.8 | cisco ios Multiple vulnerabilities in the Cisco IOx application environment of Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) that are running Cisco IOS Software could allow an attacker t | 0.7% | — |
| CVE-2026-68079 | CRIT 9.8 | apache cxf In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the implementation of the removeCodeGrant functionality. This violates the RFC requirement that "The authorization co | 0.7% | — |