57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-54113 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2025-59499 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2022-45048 | HIGH 8.4 | apache ranger Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. | 1.1% | — |
| CVE-2015-4324 | MED 6.1 | cisco nx-os Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to caus | 1.1% | — |
| CVE-2025-49701 | HIGH 8.8 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-27309 | HIGH 7.4 | apache kafka While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated wit | 1.1% | — |
| CVE-2023-21526 | HIGH 7.4 | microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-0004 | MED 6.5 | fedoraproject fedora A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity | 1.1% | — |
| CVE-2022-3640 | MED 5.5 | debian debian_linux A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patc | 1.1% | — |
| CVE-2022-20726 | MED 5.5 | cisco cgr1000_compute_module Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 1.1% | — |
| CVE-2018-13102 | HIGH 7.8 | anydesk anydesk AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability. | 1.1% | — |
| CVE-2008-1471 | HIGH 7.2 | panda panda_antivirus_and_firewall The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-b | 1.1% | — |
| CVE-2026-45648 | HIGH 8.8 | microsoft windows_server_2022 Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-49069 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21743 | MED 5.3 | microsoft sharepoint_server Microsoft SharePoint Server Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2021-26886 | MED 6.1 | microsoft windows_10 User Profile Service Denial of Service Vulnerability | 1.1% | — |
| CVE-2020-14999 | HIGH 7.5 | acronis agent A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data. | 1.1% | — |
| CVE-2018-9192 | MED 5.9 | fortinet fortios A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under S | 1.1% | — |
| CVE-2015-7829 | LOW 1.9 | adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows mishandle junctions in the Synchronizer directory, | 1.1% | — |
| CVE-2015-0676 | HIGH 7.1 | cisco adaptive_security_appliance_software The DNS implementation in Cisco Adaptive Security Appliance (ASA) Software 7.2 before 7.2(5.16), 8.2 before 8.2(5.57), 8.3 before 8.3(2.44), 8.4 before 8.4(7.28), 8.5 before 8.5(1.24), 8.6 before 8.6(1.17), 8.7 before 8.7(1.16), 9.0 before 9.0(4.33), 9.1 befor | 1.1% | — |
| CVE-2023-36851 | MED 5.3 | juniper junos A Missing Authentication for Critical Function vulnerability in Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause limited impact to the file system integrity. With a specific request to webauth_operation.ph | 1.1% | |
| CVE-2022-41057 | HIGH 7.8 | microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2012-0903 | MED 4.3 | vmware zimbra_desktop Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Desktop 7.1.2 b10978 allow remote attackers to inject arbitrary web script or HTML via the (1) Username or (2) MailBox Name. | 1.1% | — |
| CVE-2024-43467 | HIGH 7.5 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-20873 | CRIT 9.8 | vmware spring_boot In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users sho | 1.1% | — |