58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-37141 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::ProfilingHelpers::ProfiledNewScArray(). | 0.8% | — |
| CVE-2023-37140 | MED 5.5 | microsoft chakracore ChakraCore branch master cbb9b was discovered to contain a segmentation violation via the function Js::DiagScopeVariablesWalker::GetChildrenCount(). | 0.8% | — |
| CVE-2023-20254 | HIGH 7.2 | cisco sd-wan_manager A vulnerability in the session management system of the Cisco Catalyst SD-WAN Manager multi-tenant feature could allow an authenticated, remote attacker to access another tenant that is being managed by the same Cisco Catalyst SD-WAN Manager instance. This vul | 0.8% | — |
| CVE-2022-40733 | MED 5.0 | microsoft windows_11_21h2 An access violation vulnerability exists in the DirectComposition functionality win32kbase.sys driver version 10.0.22000.593 as part of Windows 11 version 22000.593 and version 10.0.20348.643 as part of Windows Server 2022 version 20348.643. A specially-crafte | 0.8% | — |
| CVE-2022-38652 | CRIT 9.9 | vmware hyperic_agent A remote insecure deserialization vulnerability exixsts in VMWare Hyperic Agent 5.8.6. Exploitation of this vulnerability enables a malicious authenticated user to run arbitrary code or malware within a Hyperic Agent instance and its host operating system with | 0.8% | — |
| CVE-2020-2017 | HIGH 8.8 | paloaltonetworks pan-os A DOM-Based Cross Site Scripting Vulnerability exists in PAN-OS and Panorama Management Web Interfaces. A remote attacker able to convince an authenticated administrator to click on a crafted link to PAN-OS and Panorama Web Interfaces could execute arbitrary J | 0.8% | — |
| CVE-2020-1637 | HIGH 7.2 | juniper junos A vulnerability in Juniper Networks SRX Series device configured as a Junos OS Enforcer device may allow a user to access network resources that are not permitted by a UAC policy. This issue might occur when the IP address range configured in the Infranet Cont | 0.8% | — |
| CVE-2019-19150 | MED 4.9 | f5 big-ip_access_policy_manager On versions 15.0.0-15.0.1.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.2-11.6.5.1, the BIG-IP APM system logs the client-session-id when a per-session policy is attached to the virtual server with debug logging enabled. | 0.8% | — |
| CVE-2018-18517 | MED 4.8 | citrix netscaler_gateway_firmware Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS. | 0.8% | — |
| CVE-2005-2800 | LOW 2.1 | linux linux_kernel Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows local users to cause a denial of service (memory consumption) via certain repeated reads from the /proc/scsi/sg/devices file, which is not | 0.8% | — |
| CVE-2026-53266 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the brid | 0.8% | |
| CVE-2026-46454 | CRIT 9.8 | apache camel Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers into the Camel Exchange without applying a HeaderFilterStrategy. CometdBinding.populateExchangeFromMessage copies | 0.8% | — |
| CVE-2026-43037 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() Oskar Kjos reported the following problem. ip4ip6_err() calls icmp_send() on a cloned skb whose cb[] was written by the IPv6 receive path as str | 0.8% | — |
| CVE-2026-24098 | MED 6.5 | apache airflow Apache Airflow versions 3.0.0 - 3.1.7, has vulnerability that allows authenticated UI users with permission to one or more specific Dags to view import errors generated by other Dags they did not have access to. Users are advised to upgrade to 3.1.7 or later | 0.8% | — |
| CVE-2024-8196 | CRIT 9.8 | mintplexlabs anythingllm_desktop In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as | 0.8% | — |
| CVE-2024-38169 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-35260 | HIGH 8.0 | microsoft power_platform An authenticated attacker can exploit an untrusted search path vulnerability in Microsoft Dataverse to execute code over a network. | 0.8% | — |
| CVE-2023-33305 | MED 4.9 | fortinet fortios A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions, FortiProxy version 7.2.0 through 7.2. | 0.8% | — |
| CVE-2022-22169 | MED 5.9 | juniper junos An Improper Initialization vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker who sends specific packets in certain orders and at specific timings to force OSPFv3 to unexpectedly enter gracef | 0.8% | — |
| CVE-2021-41345 | HIGH 7.8 | microsoft windows_10 Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1130 | MED 4.8 | cisco catalyst_center A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists beca | 0.8% | — |
| CVE-2021-0129 | MED 5.7 | bluez bluez Improper access control in BlueZ may allow an authenticated user to potentially enable information disclosure via adjacent access. | 0.8% | — |
| CVE-2019-1673 | MED 5.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to in | 0.8% | — |
| CVE-2011-3363 | MED 6.5 | linux linux_kernel The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share. | 0.8% | — |
| CVE-2026-69793 | HIGH 7.5 | microsoft windows_10_1607 Improper validation of consistency within input in Windows TCP/IP allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |