IT
57.811 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.811 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-0062 HIGH 7.5 juniper junos A session fixation vulnerability in J-Web on Junos OS may allow an attacker to use social engineering techniques to fix and hijack a J-Web administrators web session and potentially gain administrative access to the device. This issue affects: Juniper Networks 1.1%
CVE-2018-8455 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windo 1.1%
CVE-2018-8232 HIGH 7.8 microsoft visual_studio_2017 A Tampering vulnerability exists when Microsoft Macro Assembler improperly validates code, aka "Microsoft Macro Assembler Tampering Vulnerability." This affects Microsoft Visual Studio. 1.1%
CVE-2018-1286 MED 6.5 apache openmeetings In Apache OpenMeetings 3.0.0 - 4.0.1, CRUD operations on privileged users are not password protected allowing an authenticated attacker to deny service for privileged users. 1.1%
CVE-2015-6354 LOW 3.5 cisco firesight_system_software Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.4.1.3 and 6.0 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuv73338. 1.1%
CVE-2015-6353 LOW 3.5 cisco firesight_system_software Multiple cross-site scripting (XSS) vulnerabilities in Cisco FireSight Management Center (MC) 5.3.1.5 and 5.4.x through 5.4.1.3 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCuu28922. 1.1%
CVE-2026-54130 CRIT 9.8 microsoft 365_copilot Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2023-21548 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2023-21535 HIGH 8.1 microsoft windows_10_1607 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2021-31368 HIGH 7.5 juniper junos An Uncontrolled Resource Consumption vulnerability in the kernel of Juniper Networks JUNOS OS allows an unauthenticated network based attacker to cause 100% CPU load and the device to become unresponsive by sending a flood of traffic to the out-of-band managem 1.1%
CVE-2021-26889 HIGH 7.8 microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability 1.1%
CVE-2021-1133 MED 4.6 cisco data_center_network_manager Multiple vulnerabilities in the REST API endpoint of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to view, modify, and delete data without proper authorization. For more information about these vulnerabilities, see the 1.1%
CVE-2019-0892 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. 1.1%
CVE-2019-0766 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege 1.1%
CVE-2019-0696 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 1.1%
CVE-2018-8441 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1.1%
CVE-2018-7636 MED 6.1 paloaltonetworks pan-os The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs. 1.1%
CVE-2017-8466 HIGH 7.8 microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". 1.1%
CVE-2013-6694 MED 4.3 cisco ios The IPSec implementation in Cisco IOS allows remote attackers to cause a denial of service (MTU change and tunnel-session drop) via crafted ICMP packets, aka Bug ID CSCul29918. 1.1%
CVE-2013-5555 MED 4.3 cisco unified_communications_manager Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349. 1.1%
CVE-2012-5786 MED 5.8 apache cxf The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50 1.1%
CVE-2010-1244 MED 6.8 apache activemq Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue 1.1%
CVE-2025-49217 CRIT 9.8 trendmicro trend_micro_endpoint_encryption An insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49213 but is in a different method 1.1%
CVE-2024-49071 MED 6.5 microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. 1.1%
CVE-2023-42790 HIGH 8.1 fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiP 1.1%