58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-41607 | MED 6.5 | apache thrift Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0.9% | — |
| CVE-2020-3155 | HIGH 7.4 | cisco intelligence_proximity A vulnerability in the SSL implementation of the Cisco Intelligent Proximity solution could allow an unauthenticated, remote attacker to view or alter information shared on Cisco Webex video devices and Cisco collaboration endpoints if the products meet the co | 0.9% | — |
| CVE-2018-15321 | MED 4.9 | f5 big-ip_access_policy_manager When BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.2, or 11.2.1-11.5.6, BIG-IQ Centralized Management 5.0.0-5.4.0 or 4.6.0, BIG-IQ Cloud and Orchestration 1.0.0, iWorkflow 2.1.0-2.3.0, or Enterprise Manager 3.1.1 is licensed for Appli | 0.9% | — |
| CVE-2009-0743 | LOW 3.5 | cisco unified_meetingplace Cross-site scripting (XSS) vulnerability in the edit account page in the Web Server in Cisco Unified MeetingPlace Web Conferencing 6.0 before 6.0(517.0) (aka 6.0 MR4) and 7.0 before 7.0(2) (aka 7.0 MR1) allows remote authenticated users to inject arbitrary web | 0.9% | — |
| CVE-2024-30327 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader template Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0.9% | — |
| CVE-2024-26578 | MED 5.9 | apache answer Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Answer.This issue affects Apache Answer: through 1.2.1. Repeated submission during registration resulted in the registration of the same user. | 0.9% | — |
| CVE-2022-2590 | HIGH 7.0 | linux linux_kernel A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, incr | 0.9% | — |
| CVE-2022-23023 | MED 6.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2.1, 15.1.x before 15.1.5, 14.1.x before 14.1.4.5, and all versions of 13.1.x and 12.1.x, and BIG-IQ all versions of 8.x and 7.x, undisclosed requests by an authenticated iControl REST user can cause an increase in memory r | 0.9% | — |
| CVE-2020-3163 | MED 5.9 | cisco unified_contact_center_enterprise A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improp | 0.9% | — |
| CVE-2019-6675 | CRIT 9.8 | f5 big-ip_access_policy_manager BIG-IP configurations using Active Directory, LDAP, or Client Certificate LDAP for management authentication with multiple servers are exposed to a vulnerability which allows an authentication bypass. This can result in a complete compromise of the system. Thi | 0.9% | — |
| CVE-2015-0759 | MED 6.8 | cisco headend_digital_broadband_delivery_system Cross-site request forgery (CSRF) vulnerability in Cisco Headend Digital Broadband Delivery System allows remote attackers to hijack the authentication of arbitrary users. | 0.9% | — |
| CVE-2007-2037 | LOW 2.9 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) before 3.2.116.21, and 4.0.x before 4.0.155.0, allows remote attackers on a local network to cause a denial of service (device crash) via malformed Ethernet traffic. | 0.9% | — |
| CVE-2026-69723 | MED 5.7 | microsoft windows_10_1607 Exposure of sensitive system information to an unauthorized control sphere in Windows Kernel allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69591 | MED 5.7 | microsoft windows_10_1809 Out-of-bounds read in Windows NTFS allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69572 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69552 | MED 5.7 | microsoft windows_10_1607 Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69507 | MED 5.7 | microsoft windows_11_23h2 Insertion of sensitive information into externally-accessible file or directory in Microsoft Windows Search Component allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69393 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows Spaceport.sys allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69349 | MED 5.7 | microsoft windows_10_1607 Use of uninitialized resource in Windows Management Instrumentation allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69317 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-68874 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-65812 | MED 6.8 | microsoft teams Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-42533 | HIGH 8.1 | f5 nginx_gateway_fabric A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieve | 0.9% | — |
| CVE-2026-26118 | HIGH 8.8 | microsoft azure_mcp_server Server-side request forgery (ssrf) in Azure MCP Server allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2025-20115 | HIGH 8.6 | cisco ios_xr A vulnerability in confederation implementation for the Border Gateway Protocol (BGP) in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to a memory corruptio | 0.9% | — |