IT
58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2025-21994 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field of smb_acl parse_dcal() validate num_aces to allocate posix_ace_state_array. if (num_aces > ULONG_MAX / sizeof(struct smb_ace *)) It is a 0.3% —
CVE-2025-21906 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anything at all because IWL_ 0.2% —
CVE-2025-13855 HIGH 7.6 ibm storage_protect_server IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. 0.3% —
CVE-2025-13214 HIGH 7.6 ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. 0.4% —
CVE-2025-0966 HIGH 7.6 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. 0.3% —
CVE-2024-57899 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix mbss changed flags corruption on 32 bit systems On 32-bit systems, the size of an unsigned long is 4 bytes, while a u64 is 8 bytes. Therefore, when using or_each_set_bit( 0.3% —
CVE-2024-56590 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet This fixes not checking if skb really contains an ACL header otherwise the code may attempt to access some uninitilized 0.3% —
CVE-2024-49053 HIGH 7.6 microsoft dynamics_365_sales Microsoft Dynamics 365 Sales Spoofing Vulnerability 0.6% —
CVE-2024-48988 HIGH 7.6 apache streampark SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (Sprin 0.6% —
CVE-2024-47714 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: use hweight16 to get correct tx antenna The chainmask is u16 so using hweight8 cannot get correct tx_ant. Without this patch, the tx_ant of band 2 would be -1 and lead to 0.3% —
CVE-2024-43579 HIGH 7.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7% —
CVE-2024-43578 HIGH 7.6 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 0.7% —
CVE-2024-43476 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.9% —
CVE-2024-43474 HIGH 7.6 microsoft sql_server_2017 Microsoft SQL Server Information Disclosure Vulnerability 1.3% —
CVE-2024-42133 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Ignore too large handle values in BIG hci_le_big_sync_established_evt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be e 0.3% —
CVE-2024-42132 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caus 0.3% —
CVE-2024-36968 HIGH 7.6 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. M 0.3% —
CVE-2024-3661 HIGH 7.6 cisco anyconnect_vpn_client DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network c 4.1% —
CVE-2024-35267 HIGH 7.6 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 1.6% —
CVE-2024-35266 HIGH 7.6 microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability 1.6% —
CVE-2024-30048 HIGH 7.6 microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability 1.0% —
CVE-2024-30047 HIGH 7.6 microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability 1.0% —
CVE-2024-27783 HIGH 7.6 fortinet fortiaiops Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious 0.3% —
CVE-2024-21419 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 1.1% —
CVE-2024-21396 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability 1.2% —