57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-33165 | MED 4.3 | microsoft sharepoint_server Microsoft SharePoint Server Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2021-21057 | MED 6.6 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a null pointer dereference vulnerability when parsing a specially crafted PDF file. An unauthenticated attacker coul | 1.1% | — |
| CVE-2019-1340 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege | 1.1% | — |
| CVE-2017-3798 | MED 6.1 | cisco unified_communications_manager A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. More Information: | 1.1% | — |
| CVE-2014-7822 | HIGH 7.2 | linux linux_kernel The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified ot | 1.1% | — |
| CVE-2025-26687 | HIGH 7.5 | microsoft 365_copilot Use after free in Windows Win32K - GRFX allows an unauthorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2023-24911 | MED 4.3 | microsoft windows_10_1607 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | 1.1% | — |
| CVE-2018-8404 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows 8.1, | 1.1% | — |
| CVE-2017-3810 | MED 5.4 | cisco prime_service_catalog A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Releases: | 1.1% | — |
| CVE-2012-5030 | MED 6.5 | cisco ios Cisco IOS before 15.2(4)S6 does not initialize an unspecified variable, which might allow remote authenticated users to cause a denial of service (CPU consumption, watchdog timeout, crash) by walking specific SNMP objects. | 1.1% | — |
| CVE-2010-3050 | MED 6.5 | cisco ios Cisco IOS before 12.2(33)SXI allows remote authenticated users to cause a denial of service (device reboot). | 1.1% | — |
| CVE-2022-44688 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.1% | — |
| CVE-2022-41089 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-42753 | HIGH 8.1 | fortinet fortiweb An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.x, 6.1.x, 6.0.x, 5.9.x and 5.8.x may allow an authenticated attacker to perform an | 1.1% | — |
| CVE-2021-22057 | HIGH 8.8 | vmware workspace_one_access VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 contain an authentication bypass vulnerability. A malicious actor, who has successfully provided first-factor authentication, may be able to obtain second-factor authentication provided by VMware Verify. | 1.1% | — |
| CVE-2019-6665 | CRIT 9.4 | f5 big-ip_application_security_manager On BIG-IP ASM 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, and 13.1.0-13.1.3.1, BIG-IQ 6.0.0 and 5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, an attacker with access to the device communication between the BIG-IP ASM Central Policy Builder and t | 1.1% | — |
| CVE-2017-12302 | MED 4.3 | cisco unified_communications_domain_manager A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The vulnerability is due to a la | 1.1% | — |
| CVE-2017-0102 | HIGH 7.8 | microsoft windows_10 Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7 SP1; Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 let attackers with access to targets systems gain privileges when | 1.1% | — |
| CVE-2016-6463 | MED 5.3 | cisco email_security_appliance_firmware A vulnerability in the email filtering functionality of Cisco AsyncOS Software for Cisco Email Security Appliances could allow an unauthenticated, remote attacker to bypass Advanced Malware Protection (AMP) filters that are configured for an affected device. T | 1.1% | — |
| CVE-2013-3404 | HIGH 7.5 | cisco unified_communications_manager SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug I | 1.1% | — |
| CVE-2025-49759 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2022-42444 | MED 4.9 | ibm app_connect_enterprise IBM App Connect Enterprise 11.0.0.8 through 11.0.0.19 and 12.0.1.0 through 12.0.5.0 is vulnerable to a buffer overflow. A remote privileged user could overflow a buffer and cause the application to crash. IBM X-Force ID: 238538. | 1.1% | — |
| CVE-2020-1485 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows Image Acquisition (WIA) Service improperly discloses contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s syst | 1.1% | — |
| CVE-2020-1476 | MED 5.5 | microsoft .net_framework An elevation of privilege vulnerability exists when ASP.NET or .NET web applications running on IIS improperly allow access to cached files. An attacker who successfully exploited this vulnerability could gain access to restricted files. To exploit this vulner | 1.1% | — |
| CVE-2020-1383 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in RPC if the server has Routing and Remote Access enabled. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system To exploit this vulnerability, | 1.1% | — |