IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2013-6024 MED 4.4 f5 big-ip_access_policy_manager The Edge Client components in F5 BIG-IP APM 10.x, 11.x, 12.x, 13.x, and 14.x, BIG-IP Edge Gateway 10.x and 11.x, and FirePass 7.0.0 allow attackers to obtain sensitive information from process memory via unspecified vectors. 0.4% —
CVE-2013-3434 MED 6.8 cisco unified_communications_manager Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui0 0.4% —
CVE-2013-0313 MED 6.2 linux linux_kernel The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or pos 0.4% —
CVE-2012-2384 MED 4.9 linux linux_kernel Integer overflow in the i915_gem_do_execbuffer function in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the Direct Rendering Manager (DRM) subsystem in the Linux kernel before 3.3.5 on 32-bit platforms allows local users to cause a denial of service (out-of-b 0.4% —
CVE-2012-1313 MED 6.5 cisco unified_computing_system The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macstats parameters, aka Bug ID CSCub13772. 0.4% —
CVE-2007-1271 MED 6.6 vmware esx Buffer overflow in VMware ESX Server 3.0.0 and 3.0.1 might allow attackers to gain privileges or cause a denial of service (application crash) via unspecified vectors. 0.4% —
CVE-2006-0482 LOW 2.1 linux linux_kernel Linux kernel 2.6.15.1 and earlier, when running on SPARC architectures, allows local users to cause a denial of service (hang) via a "date -s" command, which causes invalid sign extended arguments to be provided to the get_compat_timespec function call. 0.4% —
CVE-2005-1041 LOW 2.1 linux linux_kernel The fib_seq_start function in fib_hash.c in Linux kernel allows local users to cause a denial of service (system crash) via /proc/net/route. 0.4% —
CVE-2005-0977 LOW 2.1 linux linux_kernel The shmem_nopage function in shmem.c for the tmpfs driver in Linux kernel 2.6 does not properly verify the address argument, which allows local users to cause a denial of service (kernel crash) via an invalid address. 0.4% —
CVE-2002-1554 MED 4.6 cisco optical_networking_systems_software Cisco ONS15454 and ONS15327 running ONS before 3.4 stores usernames and passwords in cleartext in the image database for the TCC, TCC+ or XTC, which could allow attackers to gain privileges by obtaining the passwords from the image database or a backup. 0.4% —
CVE-2000-0267 MED 4.6 cisco catos Cisco Catalyst 5.4.x allows a user to gain access to the "enable" mode without a password. 0.4% —
CVE-2026-68969 MED 6.5 apache airflow Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoints (`PATCH /api/v2/variables` and `PATCH /api/v2/connections`). The audit-log masking recognised only top-level 0.4% —
CVE-2026-45426 LOW 3.1 apache airflow Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against Dag IDs by applying Python's `str.lstrip()` to the requested 0.4% —
CVE-2026-43055 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't initialize the aio_cmd->iocb for the ki_write_stream. When a write command fd_execute_rw_aio() is executed, we m 0.4% —
CVE-2026-34691 CRIT 9.3 adobe experience_manager Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be 0.4% —
CVE-2026-20039 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an 0.4% —
CVE-2026-19875 HIGH 7.5 langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint. 0.4% —
CVE-2025-49675 HIGH 7.8 microsoft windows_10_1507 Use after free in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49661 HIGH 7.8 microsoft windows_10_1507 Untrusted pointer dereference in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-49660 HIGH 7.8 microsoft windows_10_1507 Use after free in Windows Event Tracing allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-48839 MED 6.6 fortinet fortiadc An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions may allow an authenticated attacker to execute arbitrary code via specially craft 0.4% —
CVE-2025-48816 HIGH 7.8 microsoft windows_10_1507 Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally. 0.4% —
CVE-2025-48806 HIGH 7.8 microsoft windows_10_1507 Use after free in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. 0.4% —
CVE-2025-48805 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Microsoft MPEG-2 Video Extension allows an authorized attacker to execute code locally. 0.4% —
CVE-2025-47996 HIGH 7.8 microsoft windows_10_1507 Integer underflow (wrap or wraparound) in Windows MBT Transport driver allows an authorized attacker to elevate privileges locally. 0.4% —