58.449 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.449 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-59285 | HIGH 8.1 | vmware spring_for_graphql Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. Spring for GraphQL 2.0.0 - 2.0.4 | 0.4% | — |
| CVE-2026-55955 | MED 6.5 | apache tomcat Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9. | 0.4% | — |
| CVE-2026-41732 | HIGH 8.1 | vmware spring_for_apache_pulsar JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rat | 0.4% | — |
| CVE-2025-52948 | MED 5.9 | juniper junos An Improper Handling of Exceptional Conditions vulnerability in Berkeley Packet Filter (BPF) processing of Juniper Networks Junos OS allows an attacker, in rare cases, sending specific, unknown traffic patterns to cause the FPC and system to crash and restart. | 0.4% | — |
| CVE-2024-38179 | HIGH 8.8 | microsoft azure_stack_hci Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2024-34117 | HIGH 7.8 | adobe photoshop Photoshop Desktop versions 24.7.3, 25.9.1 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must op | 0.4% | — |
| CVE-2024-3386 | MED 5.3 | paloaltonetworks pan-os An incorrect string comparison vulnerability in Palo Alto Networks PAN-OS software prevents Predefined Decryption Exclusions from functioning as intended. This can cause traffic destined for domains that are not specified in Predefined Decryption Exclusions to | 0.4% | — |
| CVE-2023-36568 | HIGH 7.0 | microsoft 365_apps Microsoft Office Click-To-Run Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-35337 | HIGH 7.8 | microsoft windows_10_21h2 Win32k Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-26020 | MED 5.7 | craftercms crafter_cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1. | 0.4% | — |
| CVE-2023-23381 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.4% | — |
| CVE-2022-49997 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: lantiq_xrx200: restore buffer if memory allocation failed In a situation where memory allocation fails, an invalid buffer address is stored. When this descriptor is used again, the syst | 0.4% | — |
| CVE-2022-35642 | MED 5.4 | ibm infosphere_information_server "IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trus | 0.4% | — |
| CVE-2021-40683 | HIGH 7.8 | akamai enterprise_application_access In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution. | 0.4% | — |
| CVE-2021-20226 | HIGH 7.8 | linux linux_kernel A use-after-free flaw was found in the io_uring in Linux kernel, where a local attacker with a user privilege could cause a denial of service problem on the system The issue results from the lack of validating the existence of an object prior to performing ope | 0.4% | — |
| CVE-2019-17650 | HIGH 7.8 | fortinet forticlient An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local user of the system on which FortiClient is running to execute unauthorized code as root by bypassing a security ch | 0.4% | — |
| CVE-2019-16234 | MED 4.7 | canonical ubuntu_linux drivers/net/wireless/intel/iwlwifi/pcie/trans.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference. | 0.4% | — |
| CVE-2019-14898 | HIGH 7.0 | linux linux_kernel The fix for CVE-2019-11599, affecting the Linux kernel before 5.0.10 was not complete. A local user could use this flaw to obtain sensitive information, cause a denial of service, or possibly have other unspecified impacts by triggering a race condition with m | 0.4% | — |
| CVE-2018-0428 | MED 6.7 | cisco web_security_appliance A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate with valid administrator credentials. The vulnerability is due | 0.4% | — |
| CVE-2017-4934 | HIGH 8.8 | vmware fusion VMware Workstation (12.x before 12.5.8) and Fusion (8.x before 8.5.9) contain a heap buffer-overflow vulnerability in VMNAT device. This issue may allow a guest to execute code on the host. | 0.4% | — |
| CVE-2017-17449 | MED 4.7 | linux linux_kernel The __netlink_deliver_tap_skb function in net/netlink/af_netlink.c in the Linux kernel through 4.14.4, when CONFIG_NLMON is enabled, does not restrict observations of Netlink messages to a single net namespace, which allows local users to obtain sensitive info | 0.4% | — |
| CVE-2017-13695 | MED 5.5 | linux linux_kernel The acpi_ns_evaluate() function in drivers/acpi/acpica/nseval.c in the Linux kernel through 4.12.9 does not flush the operand cache and causes a kernel stack dump, which allows local users to obtain sensitive information from kernel memory and bypass the KASLR | 0.4% | — |
| CVE-2017-10663 | HIGH 7.8 | linux linux_kernel The sanity_check_ckpt function in fs/f2fs/super.c in the Linux kernel before 4.12.4 does not validate the blkoff and segno arrays, which allows local users to gain privileges via unspecified vectors. | 0.4% | — |
| CVE-2017-10603 | HIGH 7.0 | juniper junos An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate privileges and run arbitrary commands as the root user. This issue was found during internal product security testing. Affected releases are Juniper Networks Junos | 0.4% | — |
| CVE-2015-6385 | HIGH 7.2 | cisco ios The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, | 0.4% | — |