57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.825 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-42361 | HIGH 7.5 | apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL | 1.1% | — |
| CVE-2021-43221 | MED 4.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-34483 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2016-1443 | HIGH 8.1 | cisco amp_threat_grid_appliance The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malware sa | 1.1% | — |
| CVE-2016-1341 | CRIT 9.8 | cisco nx-os Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079. | 1.1% | — |
| CVE-2026-54108 | MED 6.5 | microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.1% | — |
| CVE-2025-53767 | CRIT 10.0 | microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2025-48431 | HIGH 7.5 | apache thrift Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted request | 1.1% | — |
| CVE-2024-49120 | HIGH 8.1 | microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-38375 | CRIT 9.1 | fortinet fortinac An improper authorization vulnerability [CWE-285] in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. | 1.1% | — |
| CVE-2022-34160 | MED 5.4 | ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330 | 1.1% | — |
| CVE-2022-23266 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-1232 | MED 6.5 | cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of an affected system. This vulnerability is due to insufficient acc | 1.1% | — |
| CVE-2020-3542 | MED 5.3 | cisco webex_training A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeting without providing the meeting password. The vulnerability is due to improper validation of input to API requests that are a part of meeti | 1.1% | — |
| CVE-2020-16879 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system</p> <p>To exp | 1.1% | — |
| CVE-2020-1250 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit thi | 1.1% | — |
| CVE-2020-1119 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vul | 1.1% | — |
| CVE-2020-1083 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> | 1.1% | — |
| CVE-2020-0921 | MED 5.5 | microsoft windows_10 Microsoft Graphics Component Denial of Service Vulnerability | 1.1% | — |
| CVE-2020-0914 | MED 5.5 | microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p | 1.1% | — |
| CVE-2018-15455 | MED 6.1 | cisco identity_services_engine A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of requests stored in the system's logging d | 1.1% | — |
| CVE-2017-7782 | MED 5.3 | mozilla firefox An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerab | 1.1% | — |
| CVE-2015-0658 | HIGH 7.9 | cisco nx-os The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local n | 1.1% | — |
| CVE-2026-40405 | HIGH 7.5 | microsoft windows_11_24h2 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2025-62473 | MED 6.5 | microsoft windows_10_1607 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |