IT
57.825 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.825 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-42361 HIGH 7.5 apache hertzbeat Hertzbeat is an open source, real-time monitoring system. Hertzbeat 1.6.0 and earlier declares a /api/monitor/{monitorId}/metric/{metricFull} endpoint to download job metrics. In the process, it executes a SQL query with user-controlled data, allowing for SQL 1.1%
CVE-2021-43221 MED 4.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.1%
CVE-2021-34483 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 1.1%
CVE-2016-1443 HIGH 8.1 cisco amp_threat_grid_appliance The virtual network stack on Cisco AMP Threat Grid Appliance devices before 2.1.1 allows remote attackers to bypass a sandbox protection mechanism, and consequently obtain sensitive interprocess information or modify interprocess data, via a crafted malware sa 1.1%
CVE-2016-1341 CRIT 9.8 cisco nx-os Cisco NX-OS 7.0(1)N1(1), 7.0(1)N1(3), and 7.0(4)N1(1) on Nexus 2000 Fabric Extender devices has a blank root password, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCur22079. 1.1%
CVE-2026-54108 MED 6.5 microsoft sharepoint_server External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.1%
CVE-2025-53767 CRIT 10.0 microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability 1.1%
CVE-2025-48431 HIGH 7.5 apache thrift Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted request 1.1%
CVE-2024-49120 HIGH 8.1 microsoft windows_server_2012 Windows Remote Desktop Services Remote Code Execution Vulnerability 1.1%
CVE-2022-38375 CRIT 9.1 fortinet fortinac An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user to perform some administrative operations over the FortiNAC instance via crafted HTTP POST requests. 1.1%
CVE-2022-34160 MED 5.4 ibm cics_tx IBM CICS TX Standard and Advanced 11.1 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force ID: 229330 1.1%
CVE-2022-23266 HIGH 7.8 microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability 1.1%
CVE-2021-1232 MED 6.5 cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to read arbitrary files on the underlying filesystem of an affected system. This vulnerability is due to insufficient acc 1.1%
CVE-2020-3542 MED 5.3 cisco webex_training A vulnerability in Cisco Webex Training could allow an authenticated, remote attacker to join a password-protected meeting without providing the meeting password. The vulnerability is due to improper validation of input to API requests that are a part of meeti 1.1%
CVE-2020-16879 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system</p> <p>To exp 1.1%
CVE-2020-1250 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the win32k component improperly provides kernel information. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit thi 1.1%
CVE-2020-1119 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when StartTileData.dll improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> <p>To exploit this vul 1.1%
CVE-2020-1083 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system.</p> 1.1%
CVE-2020-0921 MED 5.5 microsoft windows_10 Microsoft Graphics Component Denial of Service Vulnerability 1.1%
CVE-2020-0914 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.</p> <p 1.1%
CVE-2018-15455 MED 6.1 cisco identity_services_engine A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of requests stored in the system's logging d 1.1%
CVE-2017-7782 MED 5.3 mozilla firefox An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerab 1.1%
CVE-2015-0658 HIGH 7.9 cisco nx-os The DHCP implementation in the PowerOn Auto Provisioning (POAP) feature in Cisco NX-OS does not properly restrict the initialization process, which allows remote attackers to execute arbitrary commands as root by sending crafted response packets on the local n 1.1%
CVE-2026-40405 HIGH 7.5 microsoft windows_11_24h2 Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over a network. 1.1%
CVE-2025-62473 MED 6.5 microsoft windows_10_1607 Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.1%