58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26370 | MED 5.9 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5, and 14.1.x versions prior to 14.1.4.6, when a Session Initiation Protocol (SIP) message routing framework (MRF) application layer gateway (ALG) profile is configured on a Message | 0.8% | — |
| CVE-2022-22409 | MED 5.3 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592. | 0.8% | — |
| CVE-2022-22223 | MED 6.5 | juniper junos On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (PHP) nodes with link aggregation group (LAG) interfaces, an Improper Validation of Specified Index, Position, or Offset in Input weakness all | 0.8% | — |
| CVE-2022-22212 | HIGH 7.5 | juniper junos_os_evolved An Allocation of Resources Without Limits or Throttling vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS Evolved allows unauthenticated network based attacker to cause a Denial of Service (DoS). On all Junos Evolved platforms ho | 0.8% | — |
| CVE-2022-22205 | HIGH 7.5 | juniper junos A Missing Release of Memory after Effective Lifetime vulnerability in the Application Quality of Experience (appqoe) subsystem of the PFE of Juniper Networks Junos OS on SRX Series allows an unauthenticated network based attacker to cause a Denial of Service ( | 0.8% | — |
| CVE-2021-33751 | HIGH 7.0 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-3406 | MED 5.4 | cisco sd-wan_firmware A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-ba | 0.8% | — |
| CVE-2026-82013 | CRIT 9.9 | adobe campaign Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access to internal resources. Exploitation of | 0.8% | — |
| CVE-2025-59244 | MED 6.5 | microsoft windows_10_1507 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-58739 | MED 6.5 | microsoft windows_10_1507 Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-21215 | MED 4.6 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2024-43561 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43559 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43558 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43557 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43555 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-26238 | HIGH 7.8 | microsoft windows_10_21h2 Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-45861 | MED 6.5 | fortinet fortios An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2 | 0.8% | — |
| CVE-2022-35771 | HIGH 7.8 | microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-7877 | HIGH 8.0 | mastersoft zook_agent A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitra | 0.8% | — |
| CVE-2019-19697 | MED 6.7 | trendmicro antivirus_\+_security_2019 An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. | 0.8% | — |
| CVE-2018-10650 | HIGH 7.8 | citrix xenmobile_server There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | 0.8% | — |
| CVE-2017-6748 | MED 6.7 | cisco web_security_appliance A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-leve | 0.8% | — |
| CVE-2016-8480 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first require | 0.8% | — |
| CVE-2015-0716 | MED 6.8 | cisco unity_connection Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659. | 0.8% | — |