58.617 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.617 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-25015 | HIGH 7.5 | ibm mq IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial of service by sending HTTP requests that would consume all available resources. IBM X-Force ID: 281278. | 0.9% | — |
| CVE-2022-3523 | MED 5.3 | linux linux_kernel A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. I | 0.9% | — |
| CVE-2022-24455 | HIGH 7.8 | microsoft windows_10 Windows CD-ROM Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-22036 | MED 6.5 | vmware vrealize_automation VMware vRealize Orchestrator ((8.x prior to 8.6) contains an open redirect vulnerability due to improper path handling. A malicious actor may be able to redirect victim to an attacker controlled domain due to improper path handling in vRealize Orchestrator lea | 0.9% | — |
| CVE-2021-1420 | MED 4.7 | cisco webex_meetings A vulnerability in certain web pages of Cisco Webex Meetings could allow an unauthenticated, remote attacker to modify a web page in the context of a user's browser. The vulnerability is due to improper checks on parameter values in affected pages. An attacker | 0.9% | — |
| CVE-2020-1598 | MED 6.1 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. | 0.9% | — |
| CVE-2018-0393 | MED 6.5 | cisco mobility_services_engine_3310_firmware A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attacker to make policy changes in the Policy Builder interface. The vulnerability is due to insufficient authorization cont | 0.9% | — |
| CVE-2013-6684 | MED 6.8 | cisco wireless_lan_controller The web framework on Cisco Wireless LAN Controller (WLC) devices does not properly validate configuration parameters, which allows remote authenticated users to cause a denial of service via a crafted HTTP request, aka Bug ID CSCuh81011. | 0.9% | — |
| CVE-2026-62825 | CRIT 10.0 | microsoft azure_key_vault Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-58275 | CRIT 10.0 | microsoft azure_dns Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-48567 | CRIT 10.0 | microsoft azure_horizondb Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2024-38219 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-26167 | MED 4.3 | microsoft edge Microsoft Edge for Android Spoofing Vulnerability | 0.9% | — |
| CVE-2023-24903 | HIGH 8.1 | microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-43205 | MED 4.3 | fortinet forticlient An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and below and 6.2.9 and below may allow an unauthenticated attacker to access the confighandler webserver via external | 0.9% | — |
| CVE-2021-39085 | CRIT 9.8 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, ad | 0.9% | — |
| CVE-2021-1729 | HIGH 7.1 | microsoft windows_10 Windows Update Stack Setup Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-0278 | HIGH 8.8 | juniper junos An Improper Input Validation vulnerability in J-Web of Juniper Networks Junos OS allows a locally authenticated attacker to escalate their privileges to root over the target device. junos:18.3R3-S5 junos:18.4R3-S9 junos:19.1R3-S6 junos:19.3R2-S6 junos:19.3R3-S | 0.9% | — |
| CVE-2017-6664 | HIGH 7.5 | cisco ios_xe A vulnerability in the Autonomic Networking feature of Cisco IOS XE Software could allow an unauthenticated, remote, autonomic node to access the Autonomic Networking infrastructure of an affected system, after the certificate for the autonomic node has been r | 0.9% | — |
| CVE-2009-1556 | LOW 3.5 | cisco wvc54gca img/main.cgi on the Cisco Linksys WVC54GCA wireless video camera with firmware 1.00R22 and 1.00R24 allows remote authenticated users to read arbitrary files in img/ via a filename in the next_file parameter, as demonstrated by reading .htpasswd to obtain the a | 0.9% | — |
| CVE-2026-72950 | HIGH 8.8 | microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine | 0.9% | — |
| CVE-2026-58076 | HIGH 8.8 | apache airflow Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and instantiating it with arguments from the same blob, with no restriction on what could be imported. An operator's | 0.9% | — |
| CVE-2026-24307 | CRIT 9.3 | microsoft 365_copilot Improper validation of specified type of input in M365 Copilot allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-20927 | MED 5.3 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to deny service over a network. | 0.9% | — |
| CVE-2025-20358 | CRIT 9.4 | cisco unified_contact_center_express A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vuln | 0.9% | — |