58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38565 | MED 5.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ar5523: enable proper endpoint verification Syzkaller reports [1] hitting a warning about an endpoint in use not having an expected type to it. Fix the issue by checking for the exist | 0.7% | — |
| CVE-2024-29062 | HIGH 7.1 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-26851 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_h323: Add protection for bmp length out of range UBSAN load reports an exception of BRK#5515 SHIFT_ISSUE:Bitwise shifts that are out of bounds for their data type. v | 0.7% | — |
| CVE-2024-26845 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Add TMF to tmr_list handling An abort that is responded to by iSCSI itself is added to tmr_list but does not go to target core. A LUN_RESET that goes through tmr_list tak | 0.7% | — |
| CVE-2024-21753 | MED 5.5 | fortinet forticlient_endpoint_management_server A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.13, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8, 1.2.1 through 1.2.5 allows attacker t | 0.7% | — |
| CVE-2022-43863 | MED 6.7 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425. | 0.7% | — |
| CVE-2021-26880 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26872 | HIGH 7.8 | microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-26870 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-3462 | MED 6.3 | cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-subm | 0.7% | — |
| CVE-2020-26064 | HIGH 8.1 | cisco catalyst_sd-wan_manager A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. The vulnerability is due to improper handling of XML External Enti | 0.7% | — |
| CVE-2020-11990 | LOW 3.3 | apache cordova We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access | 0.7% | — |
| CVE-2019-18568 | HIGH 8.8 | avira free_antivirus Avira Free Antivirus 15.0.1907.1514 is prone to a local privilege escalation through the execution of kernel code from a restricted user. | 0.7% | — |
| CVE-2009-4914 | HIGH 7.8 | cisco asa_5580 Memory leak on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to cause a denial of service (memory consumption) via Subject Alternative Name fields in an X.509 certificate, aka Bug ID CSCsq17879 | 0.7% | — |
| CVE-2026-84501 | MED 5.3 | apache zookeeper An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a crafted add_auth("ensemble", ...) request containing newline characters (\n). When the ensemble name doesn't match, EnsembleAuthenticationProvi | 0.7% | — |
| CVE-2026-84439 | MED 5.3 | apache zookeeper When audit logging is enabled (zookeeper.audit.enable=true), an unauthenticated attacker can inject arbitrary fields into Apache ZooKeeper's audit log by sending a digest authentication request with tab characters (\t) embedded in the username. Because the aud | 0.7% | — |
| CVE-2026-69419 | HIGH 8.5 | microsoft azure_data_manager_for_energy Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50505 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Message Queuing allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-50500 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Netlogon allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-50340 | HIGH 8.5 | microsoft windows_11_24h2 Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-50076 | CRIT 9.1 | apache fory Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Java/JVM platforms allows a remote attacker to bypass class registration, TypeChecker, and DisallowedList checks and invoke classpath-present r | 0.7% | — |
| CVE-2025-55672 | MED 5.4 | apache superset A stored Cross-Site Scripting (XSS) vulnerability exists in Apache Superset's chart visualization. An authenticated user with permissions to edit charts can inject a malicious payload into a column's label. The payload is not properly sanitized and gets execut | 0.7% | — |
| CVE-2025-49763 | HIGH 7.5 | apache traffic_server ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traf | 0.7% | — |
| CVE-2024-45217 | HIGH 8.1 | apache solr Insecure Default Initialization of Resource vulnerability in Apache Solr. New ConfigSets that are created via a Restore command, which copy a configSet from the backup and give it a new name, are created without setting the "trusted" metadata. ConfigSets that | 0.7% | — |
| CVE-2024-43106 | HIGH 7.1 | microsoft excel A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileges, leading to a permission bypass. A malicious application could inject a library and start the program to trigger thi | 0.7% | — |