57.638 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.638 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-26431 | HIGH 7.8 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2021-26097 | HIGH 8.8 | fortinet fortisandbox An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6 may allow an authenticated attacker with access to the web GUI to execute unauthorized code or | 1.2% | — |
| CVE-2020-29478 | HIGH 7.5 | broadcom ca_service_catalog CA Service Catalog 17.2 and 17.3 contain a vulnerability in the default configuration of the Setup Utility that may allow a remote attacker to cause a denial of service condition. | 1.2% | — |
| CVE-2020-1398 | MED 6.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Lockscreen fails to properly handle Ease of Access dialog.An attacker who successfully exploited the vulnerability could execute commands with elevated permissions.The security update addresses the vu | 1.2% | — |
| CVE-2019-1065 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.2% | — |
| CVE-2018-5532 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.0.0, 12.1.0-12.1.2, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 a domain name cached within the DNS Cache of TMM may continue to be resolved by the cache even after the parent server revokes the record, if the DNS Cache is receiving a stream of requests | 1.2% | — |
| CVE-2017-11818 | MED 4.5 | microsoft windows_10 The Microsoft Windows Storage component on Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows a security feature bypass vulnerability when it fails to validate an integrity-level | 1.2% | — |
| CVE-2013-5510 | MED 4.3 | cisco adaptive_security_appliance_software The remote-access VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 7.x before 7.2(5.12), 8.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(6), 8.6.x before 8.6(1.12), 9.0.x before 9.0(3.1), and 9.1.x before 9.1(2.5), when an | 1.2% | — |
| CVE-2004-1077 | MED 5.0 | citrix metaframe_client Citrix Program Neighborhood Agent for Win32 8.00.24737 and earlier and MetaFrame Presentation Server client for WinCE before 8.33 allows remote servers to create arbitrary shortcuts on the client via a full UNC path in the AppInStartmenu directive. | 1.2% | — |
| CVE-2026-54118 | CRIT 9.8 | microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2026-54117 | CRIT 9.8 | microsoft sql_server_2016 Deserialization of untrusted data in SQL Server allows an unauthorized attacker to execute code over a network. | 1.2% | — |
| CVE-2026-35435 | HIGH 8.6 | microsoft azure_ai_foundry Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2025-38191 | HIGH 7.5 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix null pointer dereference in destroy_previous_session If client set ->PreviousSessionId on kerberos session setup stage, NULL pointer dereference error will happen. Since sess->use | 1.2% | — |
| CVE-2025-21259 | MED 5.3 | microsoft outlook Microsoft Outlook Spoofing Vulnerability | 1.2% | — |
| CVE-2024-38089 | CRIT 9.1 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.2% | — |
| CVE-2023-30465 | MED 5.3 | apache inlong Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.5.0. By manipulating the "orderType" parameter and the orderin | 1.2% | — |
| CVE-2023-28271 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 1.2% | — |
| CVE-2022-23269 | MED 5.4 | microsoft dynamics_gp Microsoft Dynamics GP Spoofing Vulnerability | 1.2% | — |
| CVE-2021-40122 | MED 5.9 | cisco meeting_server A vulnerability in an API of the Call Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper handling of large series of message requests. An at | 1.2% | — |
| CVE-2021-26612 | HIGH 8.1 | tobesoft nexacro An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code. | 1.2% | — |
| CVE-2020-27121 | MED 4.3 | cisco unified_communications_manager_im_and_presence_service A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected device to restart, resulting in a denial | 1.2% | — |
| CVE-2020-24003 | LOW 3.3 | microsoft skype Microsoft Skype through 8.59.0.77 on macOS has the disable-library-validation entitlement, which allows a local process (with the user's privileges) to obtain unprompted microphone and camera access by loading a crafted library and thereby inheriting Skype Cli | 1.2% | — |
| CVE-2015-5156 | MED 6.1 | linux linux_kernel The virtnet_probe function in drivers/net/virtio_net.c in the Linux kernel before 4.2 attempts to support a FRAGLIST feature without proper memory allocation, which allows guest OS users to cause a denial of service (buffer overflow and memory corruption) via | 1.2% | — |
| CVE-2015-4266 | MED 4.3 | cisco identity_services_engine_software The web interface in Cisco Identity Services Engine (ISE) 1.1(4.1), 1.3(106.146), and 1.3(120.135) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a | 1.2% | — |
| CVE-2012-2852 | MED 6.8 | google chrome The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, does not properly handle object linkage, which allows remote attackers to cause a denial of service (use-after-free) or possi | 1.2% | — |