58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-14806 | MED 5.7 | ibm planning_analytics_local IBM Planning Analytics Local 2.1.0 through 2.1.17 could allow an attacker to trick the caching mechanism into storing and serving sensitive, user-specific responses as publicly cacheable resources. | 0.3% | — |
| CVE-2024-53240 | MED 5.7 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xen/netfront: fix crash when removing device When removing a netfront device directly after a suspend/resume cycle it might happen that the queues have not been setup again, causing a crash | 0.6% | — |
| CVE-2024-45461 | MED 5.7 | apache cloudstack The CloudStack Quota feature allows cloud administrators to implement a quota or usage limit system for cloud resources, and is disabled by default. In environments where the feature is enabled, due to missing access check enforcements, non-administrative Clou | 0.7% | — |
| CVE-2024-43604 | MED 5.7 | microsoft outlook Outlook for Android Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2024-39528 | MED 5.7 | juniper junos A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to cause a Denial of Service (DoS).On all Junos OS and Junos Evolved platforms, if a routing-i | 0.3% | — |
| CVE-2024-35263 | MED 5.7 | microsoft dynamics_365 Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability | 1.7% | — |
| CVE-2024-21430 | MED 5.7 | microsoft windows_10_1507 Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-21306 | MED 5.7 | microsoft windows_10_21h2 Microsoft Bluetooth Driver Spoofing Vulnerability | 5.8% | — |
| CVE-2024-20695 | MED 5.7 | microsoft skype_for_business_server Skype for Business Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-20692 | MED 5.7 | microsoft windows_10_1507 Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability | 1.2% | — |
| CVE-2024-20441 | MED 5.7 | cisco nexus_dashboard A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affecte | 0.5% | — |
| CVE-2023-45725 | MED 5.7 | apache couchdb Design document functions which receive a user http request object may expose authorization or session cookie headers of the user who accesses the document. These design document functions are: * list * show * rewrite * update An attacker | 1.2% | — |
| CVE-2023-36777 | MED 5.7 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 52.0% | — |
| CVE-2023-35838 | MED 5.7 | wireguard wireguard The WireGuard client 0.5.3 on Windows insecurely configures the operating system and firewall such that traffic to a local network that uses non-RFC1918 IP addresses is blocked. This allows an adversary to trick the victim into blocking IP traffic to selected | 0.7% | — |
| CVE-2023-28401 | MED 5.7 | intel arc_a_graphics Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2023-28261 | MED 5.7 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-2737 | MED 5.7 | thalesgroup safenet_authentication_service Improper log permissions in SafeNet Authentication Service Version 3.4.0 on Windows allows an authenticated attacker to cause a denial of service via local privilege escalation. | 0.1% | — |
| CVE-2023-26020 | MED 5.7 | craftercms crafter_cms Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1. | 0.4% | — |
| CVE-2023-23784 | MED 5.7 | fortinet fortiweb A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests. | 0.6% | — |
| CVE-2023-23039 | MED 5.7 | linux linux_kernel An issue was discovered in the Linux kernel through 6.2.0-rc2. drivers/tty/vcc.c has a race condition and resultant use-after-free if a physically proximate attacker removes a VCC device while calling open(), aka a race condition between vcc_open() and vcc_rem | 0.2% | — |
| CVE-2023-21693 | MED 5.7 | microsoft windows_10 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.4% | — |
| CVE-2023-20135 | MED 5.7 | cisco ios_xr A vulnerability in Cisco IOS XR Software image verification checks could allow an authenticated, local attacker to execute arbitrary code on the underlying operating system. This vulnerability is due to a time-of-check, time-of-use (TOCTOU) race condition w | 0.1% | — |
| CVE-2023-1206 | MED 5.7 | fedoraproject fedora A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CPU usage of | 0.5% | — |
| CVE-2022-30223 | MED 5.7 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-22711 | MED 5.7 | microsoft windows_10 Windows BitLocker Information Disclosure Vulnerability | 0.5% | — |