58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-22472 | HIGH 8.8 | ibm spectrum_protect_plus_container_backup_and_restore IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control restrictions, caused | 0.9% | — |
| CVE-2021-36956 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-17076 | HIGH 7.8 | microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1596 | MED 5.4 | microsoft windows_10 <p>A information disclosure vulnerability exists when TLS components use weak hash algorithms. An attacker who successfully exploited this vulnerability could obtain information to further compromise a users's encrypted transmission channel.</p> <p>To exploit | 0.9% | — |
| CVE-2017-0563 | HIGH 7.8 | linux linux_kernel An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp | 0.9% | — |
| CVE-2014-3406 | HIGH 7.1 | cisco intrusion_prevention_system Race condition in the IP logging feature in Cisco Intrusion Prevention System (IPS) Software 7.1(7)E4 and earlier allows remote attackers to cause a denial of service (device reload) via crafted IP traffic that matches a problematic rule, aka Bug ID CSCud82085 | 0.9% | — |
| CVE-2024-37358 | HIGH 8.6 | apache james_server Similarly to CVE-2024-34055, Apache James is vulnerable to denial of service through the abuse of IMAP literals from both authenticated and unauthenticated users, which could be used to cause unbounded memory allocation and very long computations Version 3.7. | 0.9% | — |
| CVE-2024-31079 | MED 4.8 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connectio | 0.9% | — |
| CVE-2024-28917 | MED 6.2 | microsoft azure_arc_extension_microsoft.azstackhci.operator Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-20338 | HIGH 7.3 | cisco secure_client A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. A | 0.9% | — |
| CVE-2023-34324 | MED 4.9 | linux linux_kernel Closing of an event channel in the Linux kernel can result in a deadlock. This happens when the close is being performed in parallel to an unrelated Xen console action and the handling of a Xen console interrupt in an unprivileged guest. The closing of an eve | 0.9% | — |
| CVE-2023-20272 | MED 6.7 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to upload malicious files to the web root of the application. This vulnerability is due to insufficient file input validation. | 0.9% | — |
| CVE-2017-0430 | HIGH 7.8 | google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compr | 0.9% | — |
| CVE-2010-4249 | MED 4.9 | fedoraproject fedora The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted u | 0.9% | — |
| CVE-2024-20694 | MED 5.5 | microsoft windows_10_1607 Windows CoreMessaging Information Disclosure Vulnerability | 0.9% | — |
| CVE-2023-21564 | HIGH 7.1 | microsoft azure_devops_server Azure DevOps Server Cross-Site Scripting Vulnerability | 0.9% | — |
| CVE-2022-20917 | MED 4.3 | cisco jabber A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticated, remote attacker to manipulate the content of XMPP messages that are used by the affected application. This vulne | 0.9% | — |
| CVE-2021-38869 | CRIT 9.8 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341. | 0.9% | — |
| CVE-2021-25248 | MED 5.5 | trendmicro apex_one An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Ple | 0.9% | — |
| CVE-2020-1676 | HIGH 7.2 | juniper mist_cloud_ui When SAML authentication is enabled, Juniper Networks Mist Cloud UI might incorrectly handle SAML responses, allowing a remote attacker to modify a valid SAML response without invalidating its cryptographic signature to bypass SAML authentication security cont | 0.9% | — |
| CVE-2020-12820 | MED 5.4 | fortinet fortios Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary | 0.9% | — |
| CVE-2008-1113 | HIGH 7.8 | vocera_communications vocera_communications_badge Cisco Unified Wireless IP Phone 7921, when using Protected Extensible Authentication Protocol (PEAP), does not validate server certificates, which allows remote wireless access points to steal hashed passwords and conduct man-in-the-middle (MITM) attacks. | 0.9% | — |
| CVE-2006-1095 | HIGH 7.2 | apache mod_python Directory traversal vulnerability in the FileSession object in Mod_python module 3.2.7 for Apache allows local users to execute arbitrary code via a crafted session cookie. | 0.9% | — |
| CVE-2026-40859 | HIGH 8.1 | apache camel Deserialization of Untrusted Data vulnerability in Apache Camel. The camel-vertx-http component deserializes HTTP response bodies carrying the Content-Type application/x-java-serialized-object using a raw java.io.ObjectInputStream, without applying any Object | 0.9% | — |
| CVE-2026-24464 | MED 6.8 | f5 big-ip_access_policy_manager When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versi | 0.9% | — |