57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-11210 | MED 5.4 | google chrome Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium) | 0.2% | — |
| CVE-2025-0526 | MED 5.4 | octopus octopus_server In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on the host using an API endpoint. The field lacked validation which could potentially result in ways to circumvent expected workflows. | 0.3% | — |
| CVE-2025-0513 | MED 5.4 | octopus octopus_server In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message. | 0.2% | — |
| CVE-2024-56512 | MED 5.4 | apache nifi Apache NiFi 1.10.0 through 2.0.0 are missing fine-grained authorization checking for Parameter Contexts, referenced Controller Services, and referenced Parameter Providers, when creating new Process Groups. Creating a new Process Group can include binding to | 3.1% | — |
| CVE-2024-56475 | MED 5.4 | ibm txseries_for_multiplatforms IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials dis | 0.2% | — |
| CVE-2024-56341 | MED 5.4 | ibm content_navigator IBM Content Navigator 3.0.11, 3.0.15, and 3.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials | 0.2% | — |
| CVE-2024-54183 | MED 5.4 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering | 0.2% | — |
| CVE-2024-53679 | MED 5.4 | apache vcl Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache VCL in the User Lookup form. A user with sufficient rights to be able to view this part of the site can craft a URL or be tricked in to clicking a URL | 0.5% | — |
| CVE-2024-52012 | MED 5.4 | apache solr Relative Path Traversal vulnerability in Apache Solr. Solr instances running on Windows are vulnerable to arbitrary filepath write-access, due to a lack of input-sanitation in the "configset upload" API. Commonly known as a "zipslip", maliciously constructed | 47.2% | — |
| CVE-2024-49337 | MED 5.4 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to HTML injection, caused by improper validation of user-supplied input of text fields used to construct workflow email notifications. A remote authenticated attacker could exploit this vu | 0.3% | — |
| CVE-2024-49025 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | 0.5% | — |
| CVE-2024-48019 | MED 5.4 | apache doris Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or Directories Accessible to External Parties vulnerability in Apache Doris. Application administrators can read arbitrary files from the server filesystem through path tra | 1.0% | — |
| CVE-2024-45761 | MED 5.4 | dell openmanage_server_administrator Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the pos | 0.3% | — |
| CVE-2024-43580 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.4% | — |
| CVE-2024-43176 | MED 5.4 | ibm openpages_with_watson IBM OpenPages 9.0 could allow an authenticated user to obtain sensitive information such as configurations that should only be available to privileged users. | 0.3% | — |
| CVE-2024-39863 | MED 5.4 | apache airflow Apache Airflow versions before 2.9.3 have a vulnerability that allows an authenticated attacker to inject a malicious link when installing a provider. Users are recommended to upgrade to version 2.9.3, which fixes this issue. | 1.0% | — |
| CVE-2024-39534 | MED 5.4 | juniper junos_os_evolved An Incorrect Comparison vulnerability in the local address verification API of Juniper Networks Junos OS Evolved allows an unauthenticated network-adjacent attacker to create sessions or send traffic to the device using the network and broadcast address of the | 0.7% | — |
| CVE-2024-38503 | MED 5.4 | apache syncope When editing a user, group or any object in the Syncope Console, HTML tags could be added to any text field and could lead to potential exploits. The same vulnerability was found in the Syncope Enduser, when editing “Personal Information” or “User Requests”. | 0.7% | — |
| CVE-2024-38217 | MED 5.4 | microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability | 10.0% | |
| CVE-2024-37527 | MED 5.4 | ibm openpages_with_watson IBM OpenPages with Watson 8.3 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure | 0.2% | — |
| CVE-2024-36387 | MED 5.4 | apache http_server Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. | 1.7% | — |
| CVE-2024-35280 | MED 5.4 | fortinet fortideceptor A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiDeceptor 5.3.0, FortiDeceptor 5.2.0, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDeceptor 4.3 all versions, FortiDece | 0.3% | — |
| CVE-2024-32077 | MED 5.4 | apache airflow Apache Airflow version 2.9.0 has a vulnerability that allows an authenticated attacker to inject malicious data into the task instance logs. Users are recommended to upgrade to version 2.9.1, which fixes this issue. | 1.6% | — |
| CVE-2024-30058 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.4% | — |
| CVE-2024-30057 | MED 5.4 | microsoft edge Microsoft Edge for iOS Spoofing Vulnerability | 0.4% | — |