CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,542
Total CVEs
1,542
CISA KEV
1542
Critical & High
Mar 13, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2020-8195 | High | CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. | Nov 3, 2021 | KEV |
| CVE-2020-8196 | High | CitrixApplication Delivery Controller (ADC), Gateway, and SD-WAN WANOP Appliance | Citrix ADC, Citrix Gateway, and multiple Citrix SD-WAN WANOP appliance models contain an information disclosure vulnerability. | Nov 3, 2021 | KEV |
| CVE-2019-11634 | High | CitrixWorkspace Application and Receiver for Windows | Citrix Workspace Application and Receiver for Windows contains remote code execution vulnerability resulting from local drive access preferences not being enforced into the clients' local drives. | Nov 3, 2021 | KEV |
| CVE-2020-29557 | High | D-LinkDIR-825 R1 Devices | D-Link DIR-825 R1 devices contain a buffer overflow vulnerability in the web interface that may allow for remote code execution. | Nov 3, 2021 | KEV |
| CVE-2020-8655 | High | EyesOfNetworkEyesOfNetwork | EyesOfNetwork contains an improper privilege management vulnerability that may allow a user to run commands as root via a crafted Nmap Scripting Engine (NSE) script to nmap7. | Nov 3, 2021 | KEV |
| CVE-2020-5902 | High | F5BIG-IP | F5 BIG-IP Traffic Management User Interface (TMUI) contains a remote code execution vulnerability in undisclosed pages. | Nov 3, 2021 | KEV |
| CVE-2021-22986 | High | F5BIG-IP and BIG-IQ Centralized Management | F5 BIG-IP and BIG-IQ Centralized Management contain a remote code execution vulnerability in the iControl REST interface that allows unauthenticated attackers with network access to execute system commands, create or delete files, and disable services. | Nov 3, 2021 | KEV |
| CVE-2021-35464 | High | ForgeRockAccess Management (AM) | ForgeRock Access Management (AM) Core Server allows an attacker who sends a specially crafted HTTP request to one of three endpoints (/ccversion/Version, /ccversion/Masthead, or /ccversion/ButtonFrame) to execute code in the context of the current user (unless ForgeRock AM is running as root user, which the vendor does not recommend). | Nov 3, 2021 | KEV |
| CVE-2019-5591 | High | FortinetFortiOS | Fortinet FortiOS contains a default configuration vulnerability that may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the Lightweight Directory Access Protocol (LDAP) server. | Nov 3, 2021 | KEV |
| CVE-2020-12812 | High | FortinetFortiOS | Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username. | Nov 3, 2021 | KEV |
| CVE-2018-13379 | High | FortinetFortiOS | Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests. | Nov 3, 2021 | KEV |
| CVE-2020-16010 | High | GoogleChrome for Android UI | Google Chrome for Android UI contains a heap buffer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | Nov 3, 2021 | KEV |
| CVE-2020-15999 | High | GoogleChrome FreeType | Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. | Nov 3, 2021 | KEV |
| CVE-2021-21166 | High | GoogleChromium | Google Chromium contains a race condition vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Nov 3, 2021 | KEV |
| CVE-2020-16017 | High | GoogleChrome | Google Chrome contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. | Nov 3, 2021 | KEV |
| CVE-2021-37976 | High | GoogleChromium | Google Chromium contains an information disclosure vulnerability within the core memory component that allows a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Nov 3, 2021 | KEV |
| CVE-2020-16013 | High | GoogleChromium V8 | Google Chromium V8 Engine contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Nov 3, 2021 | KEV |
| CVE-2021-30633 | High | GoogleChromium Indexed DB API | Google Chromium Indexed DB API contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Nov 3, 2021 | KEV |
| CVE-2021-21148 | High | GoogleChromium V8 | Google Chromium V8 Engine contains a heap buffer overflow vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. | Nov 3, 2021 | KEV |
| CVE-2021-37973 | High | GoogleChromium Portals | Google Chromium Portals contains a use-after-free vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects web browsers that utilize Chromium, including Google Chrome and Microsoft Edge. | Nov 3, 2021 | KEV |