57.725 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.725 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2003-1423 | MED 5.0 | petitforum petitforum Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. | 1.1% | — |
| CVE-2026-77484 | HIGH 8.8 | microsoft sql_server_2019 Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-53153 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-53148 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-53138 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-50157 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2020-15941 | MED 5.4 | fortinet forticlient_endpoint_management_server A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment | 1.1% | — |
| CVE-2025-21381 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-6792 | MED 5.5 | paloaltonetworks pan-os An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall. | 1.1% | — |
| CVE-2022-31660 | HIGH 7.8 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | 1.1% | — |
| CVE-2021-40767 | MED 5.5 | adobe character_animator Adobe Character Animator version 4.4 (and earlier) is affected by an Access of Memory Location After End of Buffer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application deni | 1.1% | — |
| CVE-2020-1995 | MED 4.9 | paloaltonetworks pan-os A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by r | 1.1% | — |
| CVE-2018-20733 | HIGH 7.5 | sas web_infrastructure_platform BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. | 1.1% | — |
| CVE-2026-21256 | HIGH 8.8 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-32896 | MED 6.5 | apache seatunnel # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url | 1.1% | — |
| CVE-2023-6795 | MED 5.5 | paloaltonetworks pan-os An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall. | 1.1% | — |
| CVE-2021-36963 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2019-19161 | HIGH 7.2 | cymiinstaller322_activex_project cymiinstaller322_activex CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due t | 1.1% | — |
| CVE-2017-0156 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle ob | 1.1% | — |
| CVE-2025-4660 | CRIT 9.8 | forescout secureconnector A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access controls on a named pipe. The pipe is accessible to the Everyone group and does not restrict remote connections, allowing any network-based at | 1.1% | — |
| CVE-2022-41120 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-3339 | MED 5.4 | cisco prime_infrastructure A vulnerability in the web-based management interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability is due to improper validation of user-submitted paramete | 1.1% | — |
| CVE-2016-8397 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user p | 1.1% | — |
| CVE-2016-2061 | HIGH 7.8 | linux linux_kernel Integer signedness error in the MSM V4L2 video driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges or cause a denial of service (array overf | 1.1% | — |
| CVE-2013-1177 | HIGH 7.5 | cisco network_admission_control_manager_and_server_system_software SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095. | 1.1% | — |