IT
57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.808 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2018-10512 HIGH 7.5 trendmicro control_manager A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS). 1.1%
CVE-2017-0193 HIGH 7.8 microsoft windows_10 Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target 1.1%
CVE-2010-3034 MED 5.0 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a differ 1.1%
CVE-2010-0575 MED 5.0 cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a differ 1.1%
CVE-2023-36024 HIGH 7.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.1%
CVE-2023-31469 HIGH 8.8 apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by 1.1%
CVE-2022-34723 MED 5.5 microsoft windows_11 Windows DPAPI (Data Protection Application Programming Interface) Information Disclosure Vulnerability 1.1%
CVE-2020-5862 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or v 1.1%
CVE-2019-1185 HIGH 7.3 microsoft windows_10 An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate 1.1%
CVE-2017-12630 MED 5.4 apache drill In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, 1.1%
CVE-2026-26115 HIGH 8.8 microsoft sql_server_2016 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2025-24860 MED 5.4 apache cassandra Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update 1.1%
CVE-2024-43604 MED 5.7 microsoft outlook Outlook for Android Elevation of Privilege Vulnerability 1.1%
CVE-2023-21717 HIGH 8.8 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Elevation of Privilege Vulnerability 1.1%
CVE-2021-34707 MED 6.5 cisco evolved_programmable_network_manager A vulnerability in the REST API of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to access sensitive data on an affected system. This vulnerability exists because the application does not sufficiently protect s 1.1%
CVE-2021-28316 MED 4.2 microsoft windows_10 Windows WLAN AutoConfig Service Security Feature Bypass Vulnerability 1.1%
CVE-2021-22129 HIGH 8.8 fortinet fortimail Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized c 1.1%
CVE-2020-3484 MED 5.3 cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an unauthenticated, remote attacker to view potentially sensitive information on an affected device. The vulnerability is due to incorrect permissions wi 1.1%
CVE-2013-2854 HIGH 7.5 google chrome Google Chrome before 27.0.1453.110 on Windows provides an incorrect handle to a renderer process in unspecified circumstances, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors. 1.1%
CVE-2025-49813 HIGH 7.2 fortinet fortiadc An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthorized code 1.1%
CVE-2025-37778 CRIT 9.8 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix dangling pointer in krb_authenticate krb_authenticate frees sess->user and does not set the pointer to NULL. It calls ksmbd_krb5_authenticate to reinitialise sess->user but that f 1.1%
CVE-2024-43550 HIGH 7.4 microsoft windows_10_1507 Windows Secure Channel Spoofing Vulnerability 1.1%
CVE-2022-21887 HIGH 7.0 microsoft windows_11 Win32k Elevation of Privilege Vulnerability 1.1%
CVE-2019-1713 HIGH 8.1 cisco adaptive_security_appliance_software A vulnerability in the web-based management interface of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to i 1.1%
CVE-2019-1665 MED 4.7 cisco hyperflex_hx_data_platform A vulnerability in the web-based management interface of Cisco HyperFlex software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vul 1.1%