58.543 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.543 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38808 | MED 4.3 | netapp active_iq_unified_manager In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application | 0.6% | — |
| CVE-2024-26235 | HIGH 7.8 | microsoft windows_server_2022_23h2 Windows Update Stack Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-2433 | MED 4.3 | paloaltonetworks pan-os An improper authorization vulnerability in Palo Alto Networks Panorama software enables an authenticated read-only administrator to upload files using the web interface and completely fill one of the disk partitions with those uploaded files, which prevents th | 0.6% | — |
| CVE-2024-20464 | HIGH 8.6 | cisco ios_xe A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient valida | 0.6% | — |
| CVE-2023-48633 | HIGH 7.8 | adobe after_effects Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in | 0.6% | — |
| CVE-2022-38457 | MED 6.3 | linux linux_kernel A use-after-free(UAF) vulnerability was found in function 'vmw_cmd_res_check' in drivers/gpu/vmxgfx/vmxgfx_execbuf.c in Linux kernel's vmwgfx driver with device file '/dev/dri/renderD128 (or Dxxx)'. This flaw allows a local attacker with a user account on the | 0.6% | — |
| CVE-2020-2016 | HIGH 7.0 | paloaltonetworks pan-os A race condition due to insecure creation of a file in a temporary directory vulnerability in PAN-OS allows for root privilege escalation from a limited linux user account. This allows an attacker who has escaped the restricted shell as a low privilege adminis | 0.6% | — |
| CVE-2014-7825 | HIGH 7.8 | linux linux_kernel kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protectio | 0.6% | — |
| CVE-2026-58608 | HIGH 8.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-50414 | HIGH 7.5 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50398 | HIGH 8.8 | microsoft windows_11_24h2 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2024-46910 | HIGH 7.1 | apache atlas An authenticated user can perform XSS and potentially impersonate another user. This issue affects Apache Atlas versions 2.3.0 and earlier. Users are recommended to upgrade to version 2.4.0, which fixes the issue. | 0.6% | — |
| CVE-2024-43640 | HIGH 7.8 | microsoft windows_10_21h2 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-20657 | HIGH 7.0 | microsoft windows_10_1507 Windows Group Policy Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-38363 | MED 4.3 | ibm cics_tx IBM CICS TX Advanced 10.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be | 0.6% | — |
| CVE-2023-21764 | HIGH 7.8 | microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-30610 | MED 4.5 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.15.0 is vulnerable to reverse tabnabbing where it could allow a page linked to from within IBM Spectrum Copy Data Management to rewrite it. An administrator could enter a link to a malicious URL that anothe | 0.6% | — |
| CVE-2021-41019 | LOW 3.5 | fortinet fortios An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credentials. | 0.6% | — |
| CVE-2021-28314 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2020-27152 | MED 5.5 | linux linux_kernel An issue was discovered in ioapic_lazy_update_eoi in arch/x86/kvm/ioapic.c in the Linux kernel before 5.9.2. It has an infinite loop related to improper interaction between a resampler and edge triggering, aka CID-77377064c3a9. | 0.6% | — |
| CVE-2019-11396 | HIGH 7.8 | avira free_security_suite An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that c | 0.6% | — |
| CVE-2018-25015 | HIGH 7.8 | linux linux_kernel An issue was discovered in the Linux kernel before 4.14.16. There is a use-after-free in net/sctp/socket.c for a held lock after a peel off, aka CID-a0ff660058b8. | 0.6% | — |
| CVE-2017-12283 | MED 6.1 | cisco aironet_3800_firmware A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device, aka Denial of Service. The vul | 0.6% | — |
| CVE-2017-12282 | MED 6.1 | cisco wireless_lan_controller_software A vulnerability in the Access Network Query Protocol (ANQP) ingress frame processing functionality of Cisco Wireless LAN Controllers could allow an unauthenticated, Layer 2 RF-adjacent attacker to cause an affected device to restart unexpectedly, resulting in | 0.6% | — |
| CVE-2015-8785 | MED 6.2 | linux linux_kernel The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov. | 0.6% | — |