57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-59245 | CRIT 9.8 | microsoft sharepoint_online Microsoft SharePoint Online Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-38033 | HIGH 7.3 | microsoft windows_10_1507 PowerShell Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-37970 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2023-36785 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-22473 | MED 5.3 | ibm websphere_application_server IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to obtain sensitive information caused by improper handling of Administrative Console data. This information could be used in further attacks against the system. IBM X-Force | 1.1% | — |
| CVE-2022-22195 | HIGH 7.5 | juniper junos_os_evolved An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to trigger a counter overflow, eventually causing a Denial of Service (DoS). This issue affects Juniper Net | 1.1% | — |
| CVE-2022-22049 | HIGH 7.8 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-34715 | MED 4.7 | cisco expressway A vulnerability in the image verification function of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker to execute code with internal user privileges on the underlying operating system | 1.1% | — |
| CVE-2021-26887 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Folder redirection has been enabled via Group Policy. When folder redirection file server is co-located with Terminal server, an attacker who successfully exploited the vulnerability woul | 1.1% | — |
| CVE-2021-22977 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.0.0-16.0.1 and 14.1.2.4-14.1.3, cooperation between malicious HTTP client code and a malicious server may cause TMM to restart and generate a core file. Note: Software versions which have reached End of Software Development (EoSD) are not | 1.1% | — |
| CVE-2021-0286 | HIGH 7.5 | juniper junos_os_evolved A vulnerability in the handling of exceptional conditions in Juniper Networks Junos OS Evolved (EVO) allows an attacker to send specially crafted packets to the device, causing the Advanced Forwarding Toolkit manager (evo-aftmand-bt or evo-aftmand-zx) process | 1.1% | — |
| CVE-2020-5950 | MED 5.3 | f5 big-ip_advanced_firewall_manager On BIG-IP 14.1.0-14.1.2.6, undisclosed endpoints in iControl REST allow for a reflected XSS attack, which could lead to a complete compromise of the BIG-IP system if the victim user is granted the admin role. | 1.1% | — |
| CVE-2020-3156 | MED 6.1 | cisco identity_services_engine A vulnerability in the logging component of Cisco Identity Services Engine could allow an unauthenticated remote attacker to conduct cross-site scripting attacks. The vulnerability is due to the improper validation of endpoint data stored in logs used by the w | 1.1% | — |
| CVE-2024-43601 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code for Linux Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-25197 | MED 6.3 | apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components. This issue affects apache finera | 1.1% | — |
| CVE-2022-35821 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.1% | — |
| CVE-2021-41016 | HIGH 7.8 | fortinet fortiextender_firmware A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands inc | 1.1% | — |
| CVE-2021-40440 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1.1% | — |
| CVE-2021-32586 | HIGH 7.7 | fortinet fortimail An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests. | 1.1% | — |
| CVE-2020-4383 | MED 6.5 | ibm elastic_storage_server IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment while configuring some of the network services. IBM X-Force ID: 179165. | 1.1% | — |
| CVE-2020-0731 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020- | 1.1% | — |
| CVE-2020-0635 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644. | 1.1% | — |
| CVE-2019-0973 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system | 1.1% | — |
| CVE-2017-14190 | MED 6.1 | fortinet fortios A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests. | 1.1% | — |
| CVE-2017-10610 | HIGH 7.5 | juniper junos On SRX Series devices, a crafted ICMP packet embedded within a NAT64 IPv6 to IPv4 tunnel may cause the flowd process to crash. Repeated crashes of the flowd process constitutes an extended denial of service condition for the SRX Series device. This issue only | 1.1% | — |