58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-21994 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix incorrect validation for num_aces field of smb_acl parse_dcal() validate num_aces to allocate posix_ace_state_array. if (num_aces > ULONG_MAX / sizeof(struct smb_ace *)) It is a | 0.3% | — |
| CVE-2025-21906 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: mvm: clean up ROC on failure If the firmware fails to start the session protection, then we do call iwl_mvm_roc_finished() here, but that won't do anything at all because IWL_ | 0.2% | — |
| CVE-2025-13855 | HIGH 7.6 | ibm storage_protect_server IBM Storage Protect Server 8.2.0 IBM Storage Protect Plus Server is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | 0.3% | — |
| CVE-2025-13214 | HIGH 7.6 | ibm aspera_orchestrator IBM Aspera Orchestrator 4.0.0 through 4.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | 0.4% | — |
| CVE-2025-0966 | HIGH 7.6 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database. | 0.3% | — |
| CVE-2024-57899 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix mbss changed flags corruption on 32 bit systems On 32-bit systems, the size of an unsigned long is 4 bytes, while a u64 is 8 bytes. Therefore, when using or_each_set_bit( | 0.3% | — |
| CVE-2024-56590 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix not checking skb length on hci_acldata_packet This fixes not checking if skb really contains an ACL header otherwise the code may attempt to access some uninitilized | 0.3% | — |
| CVE-2024-49053 | HIGH 7.6 | microsoft dynamics_365_sales Microsoft Dynamics 365 Sales Spoofing Vulnerability | 0.6% | — |
| CVE-2024-48988 | HIGH 7.6 | apache streampark SQL Injection vulnerability in Apache StreamPark. This issue affects Apache StreamPark: from 2.1.4 before 2.1.6. Users are recommended to upgrade to version 2.1.6, which fixes the issue. This vulnerability is present only in the distribution package (Sprin | 0.6% | — |
| CVE-2024-47714 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: use hweight16 to get correct tx antenna The chainmask is u16 so using hweight8 cannot get correct tx_ant. Without this patch, the tx_ant of band 2 would be -1 and lead to | 0.3% | — |
| CVE-2024-43579 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43578 | HIGH 7.6 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-43476 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2024-43474 | HIGH 7.6 | microsoft sql_server_2017 Microsoft SQL Server Information Disclosure Vulnerability | 1.3% | — |
| CVE-2024-42133 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Ignore too large handle values in BIG hci_le_big_sync_established_evt is necessary to filter out cases where the handle value is belonging to ida id range, otherwise ida will be e | 0.3% | — |
| CVE-2024-42132 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bluetooth/hci: disallow setting handle bigger than HCI_CONN_HANDLE_MAX Syzbot hit warning in hci_conn_del() caused by freeing handle that was not allocated using ida allocator. This is caus | 0.3% | — |
| CVE-2024-36968 | HIGH 7.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix div-by-zero in l2cap_le_flowctl_init() l2cap_le_flowctl_init() can cause both div-by-zero and an integer overflow since hdev->le_mtu may not fall in the valid range. M | 0.3% | — |
| CVE-2024-3661 | HIGH 7.6 | cisco anyconnect_vpn_client DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network c | 4.1% | — |
| CVE-2024-35267 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-35266 | HIGH 7.6 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.6% | — |
| CVE-2024-30048 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2024-30047 | HIGH 7.6 | microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability | 1.0% | — |
| CVE-2024-27783 | HIGH 7.6 | fortinet fortiaiops Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attacker to perform arbitrary actions on behalf of an authenticated user via tricking the victim to execute malicious | 0.3% | — |
| CVE-2024-21419 | HIGH 7.6 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.1% | — |
| CVE-2024-21396 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability | 1.2% | — |