58.290 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.290 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2008-0967 | MED 6.9 | vmware esx Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on | 0.4% | — |
| CVE-2006-0485 | MED 4.6 | cisco ios The TCL shell in Cisco IOS 12.2(14)S before 12.2(14)S16, 12.2(18)S before 12.2(18)S11, and certain other releases before 25 January 2006 does not perform Authentication, Authorization, and Accounting (AAA) command authorization checks, which may allow local us | 0.4% | — |
| CVE-2004-1902 | LOW 2.1 | citrix metaframe_password_manager The Citrix MetaFrame Password Manager 2.0, when a central credential store is not configured, does not encrypt passwords entered immediately after executing the First Time User Wizards, which allows local users to gain sensitive information. | 0.4% | — |
| CVE-2026-66390 | MED 6.1 | apache wicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 9.0.0 through 9.23.0, from 10.0.0 through 10.9.0. Users are recommended to upgrade to version 10.10.0, | 0.4% | — |
| CVE-2026-64400 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting caseless retry ksmbd_vfs_path_lookup() enforces LOOKUP_BENEATH to restrict path resolution within the share root. When a crafted path atte | 0.4% | — |
| CVE-2026-50623 | MED 4.8 | apache cxf An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated | 0.4% | — |
| CVE-2026-45607 | HIGH 8.4 | microsoft windows_10_1607 Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally. | 0.4% | — |
| CVE-2026-42509 | MED 6.1 | apache wicket Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket. This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 through 10.8.0. Users are recommended to upgrade to version 1 | 0.4% | — |
| CVE-2026-20286 | MED 4.3 | A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side vali | 0.4% | — |
| CVE-2026-20285 | MED 4.3 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This v | 0.4% | — |
| CVE-2025-55230 | HIGH 7.8 | microsoft windows_10_1507 Untrusted pointer dereference in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53782 | HIGH 8.4 | microsoft exchange_server Incorrect implementation of authentication algorithm in Microsoft Exchange Server allows an unauthorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53721 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53140 | HIGH 7.0 | microsoft windows_10_1507 Use after free in Kernel Transaction Manager allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-53133 | HIGH 7.8 | microsoft windows_11_24h2 Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-39770 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: net: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM When performing Generic Segmentation Offload (GSO) on an IPv6 packet that contains extension headers, the kernel inco | 0.4% | — |
| CVE-2025-3940 | MED 5.3 | tridium niagara Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15. | 0.4% | — |
| CVE-2025-20285 | MED 4.1 | cisco identity_services_engine A vulnerability in the IP Access Restriction feature of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to bypass configured IP access restrictions and log in to the device from a disallowed IP address. This vulnerability is due to | 0.4% | — |
| CVE-2025-0104 | MED 6.1 | paloaltonetworks expedition A reflected cross-site scripting (XSS) vulnerability in Palo Alto Networks Expedition enables attackers to execute malicious JavaScript code in the context of an authenticated Expedition user’s browser if that authenticated user clicks a malicious link that al | 0.4% | — |
| CVE-2024-45654 | MED 4.3 | ibm security_qradar_edr IBM Security ReaQta 3.12 could allow an authenticated user to perform unauthorized actions due to reliance on untrusted inputs. | 0.4% | — |
| CVE-2023-21584 | MED 5.5 | adobe framemaker FrameMaker 2020 Update 4 (and earlier), 2022 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this | 0.4% | — |
| CVE-2022-50386 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix user-after-free This uses l2cap_chan_hold_unless_zero() after calling __l2cap_get_chan_blah() to prevent the following trace: Bluetooth: l2cap_core.c:static void l2cap | 0.4% | — |
| CVE-2022-49114 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: libfc: Fix use after free in fc_exch_abts_resp() fc_exch_release(ep) will decrease the ep's reference count. When the reference count reaches zero, it is freed. But ep is still used in | 0.4% | — |
| CVE-2022-24505 | HIGH 7.0 | microsoft windows_10 Windows ALPC Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2021-34729 | MED 6.7 | cisco ios_xe A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to insufficient validation | 0.4% | — |