58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-35425 | HIGH 8.0 | microsoft azure_api_management Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-26685 | MED 6.5 | microsoft defender_for_identity Improper authentication in Microsoft Defender for Identity allows an unauthorized attacker to perform spoofing over an adjacent network. | 0.7% | — |
| CVE-2025-21396 | HIGH 8.2 | microsoft account Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-56626 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write An offset from client could be a negative value, It could allows to write data outside the bounds of the allocated buffer. Note that | 0.7% | — |
| CVE-2024-36448 | HIGH 7.3 | apache iotdb_workbench ** UNSUPPORTED WHEN ASSIGNED ** Server-Side Request Forgery (SSRF) vulnerability in Apache IoTDB Workbench. This issue affects Apache IoTDB Workbench: from 0.13.0. As this project is retired, we do not plan to release a version that fixes this issue. Users a | 0.7% | — |
| CVE-2024-20681 | HIGH 7.8 | microsoft windows_10_21h2 Windows Subsystem for Linux Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-41151 | HIGH 7.5 | softing opc An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing. | 0.7% | — |
| CVE-2023-24947 | HIGH 8.8 | microsoft windows_10_1607 Windows Bluetooth Driver Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-23781 | MED 6.4 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted XML | 0.7% | — |
| CVE-2022-33947 | MED 5.4 | f5 big-ip_domain_name_system In BIG-IP Versions 16.1.x before 16.1.3, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, a vulnerability exists in undisclosed pages of the BIG-IP DNS Traffic Management User Interface (TMUI) that allows an authenticated attacker with | 0.7% | — |
| CVE-2020-3507 | HIGH 8.8 | cisco 8000p_ip_camera_firmware Multiple vulnerabilities in the Cisco Discovery Protocol implementation for Cisco Video Surveillance 8000 Series IP Cameras could allow an unauthenticated, adjacent attacker to execute code remotely or cause a reload of an affected IP camera. These vulnerabili | 0.7% | — |
| CVE-2020-11862 | HIGH 8.6 | opentext netiq_privileged_account_manager Allocation of Resources Without Limits or Throttling vulnerability in OpenText NetIQ Privileged Account Manager on Linux, Windows, 64 bit allows Flooding.This issue affects NetIQ Privileged Account Manager: before 3.7.0.2. | 0.7% | — |
| CVE-2019-19039 | MED 5.5 | canonical ubuntu_linux __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program. NOTE: The BTRFS | 0.7% | — |
| CVE-2017-12339 | MED 5.7 | cisco lan_switch_software A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments to the CLI parser. An attacker could ex | 0.7% | — |
| CVE-2005-0852 | LOW 2.1 | Microsoft Windows XP SP1 allows local users to cause a denial of service (system crash) via an empty datagram to a raw IP over IP socket (IP protocol 4), as originally demonstrated using code in Python 2.3. | 0.7% | — |
| CVE-2026-64397 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: serialize QUERY_DIRECTORY requests per file smb2_query_dir() stores a pointer to its stack-allocated private data in the ksmbd_file readdir_data. Concurrent QUERY_DIRECTORY requests u | 0.7% | — |
| CVE-2026-50369 | HIGH 8.8 | microsoft windows_10_1607 Use after free in Windows Remote Desktop Services allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-21515 | CRIT 9.9 | microsoft azure_iot_central Exposure of sensitive information to an unauthorized actor in Azure IOT Central allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2023-49322 | HIGH 7.5 | f-secure atlant Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSec | 0.7% | — |
| CVE-2023-47264 | HIGH 7.5 | withsecure atlant Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure E | 0.7% | — |
| CVE-2023-47263 | HIGH 7.5 | withsecure atlant Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoi | 0.7% | — |
| CVE-2023-40683 | HIGH 8.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 could allow remote attacker to bypass security restrictions, caused by insufficient authorization checks. By authenticating as an OpenPages user and using non-public APIs, an attacker could exploit this vulnerability to by | 0.7% | — |
| CVE-2022-43946 | HIGH 7.5 | fortinet forticlient Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on | 0.7% | — |
| CVE-2021-26582 | MED 6.1 | hp icewall_sso_dgfw A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS). | 0.7% | — |
| CVE-2009-0676 | LOW 2.1 | linux linux_kernel The sock_getsockopt function in net/core/sock.c in the Linux kernel before 2.6.28.6 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel memory via an SO_BSDCOMPAT getsockopt request. | 0.7% | — |