IT
58.560 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.560 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-102489 CRIT 9.8 zammad zammad Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions. 0.6%
CVE-2025-33062 MED 5.5 microsoft windows_10_1607 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.6% —
CVE-2025-33055 MED 5.5 microsoft windows_10_1507 Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. 0.6% —
CVE-2024-45772 MED 5.1 apache lucene_replicator Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator. This issue affects Apache Lucene's replicator module: from 4.4.0 before 9.12.0. The deprecated org.apache.lucene.replicator.http package is affected. The org.apache.lucene.replicator 0.6% —
CVE-2024-31156 HIGH 8.0 f5 big-ip_access_policy_manager A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Te 0.6% —
CVE-2024-29052 HIGH 7.8 microsoft windows_10_21h2 Windows Storage Elevation of Privilege Vulnerability 0.6% —
CVE-2023-44182 HIGH 7.3 juniper junos An Unchecked Return Value vulnerability in the user interfaces to the Juniper Networks Junos OS and Junos OS Evolved, the CLI, the XML API, the XML Management Protocol, the NETCONF Management Protocol, the gNMI interfaces, and the J-Web User Interfaces causes 0.6% —
CVE-2022-28356 MED 5.5 debian debian_linux In the Linux kernel before 5.17.1, a refcount leak bug was found in net/llc/af_llc.c. 0.6% —
CVE-2022-21866 HIGH 7.0 microsoft windows_10 Windows System Launcher Elevation of Privilege Vulnerability 0.6% —
CVE-2022-20861 CRIT 9.8 cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit 0.6% —
CVE-2022-20772 MED 4.7 cisco email_security_appliance_firmware A vulnerability in Cisco Email Security Appliance (ESA) and Cisco Secure Email and Web Manager could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. This vulnerability is due to the failure of the application or its e 0.6% —
CVE-2021-40477 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.6% —
CVE-2021-34793 HIGH 8.6 cisco adaptive_security_appliance A vulnerability in the TCP Normalizer of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software operating in transparent mode could allow an unauthenticated, remote attacker to poison MAC address tables, resulting in a den 0.6% —
CVE-2019-12573 HIGH 7.1 londontrustmedia private_internet_access_vpn_client A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log opt 0.6% —
CVE-2019-11550 MED 5.9 citrix netscaler_sd-wan Citrix SD-WAN 10.2.x before 10.2.1 and NetScaler SD-WAN 10.0.x before 10.0.7 have Improper Certificate Validation. 0.6% —
CVE-2016-4470 MED 5.5 linux linux_kernel The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl 0.6% —
CVE-2015-4186 HIGH 7.2 cisco virtualization_experience_client_6000_series_firmware The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug5 0.6% —
CVE-2015-4183 HIGH 7.2 cisco unified_computing_system Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795. 0.6% —
CVE-2000-1247 LOW 2.1 apache jserv The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwords or other sensitive information via a direct request to the jserv/ URI. 0.6% —
CVE-2026-76423 CRIT 10.0 A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device. This vulnerability is due to the REST API web service being exposed with insufficient authori 0.6% —
CVE-2026-64922 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6% —
CVE-2026-64916 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6% —
CVE-2026-64902 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6% —
CVE-2026-64897 MED 4.6 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 0.6% —
CVE-2026-64091 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct 0.6% —