57.954 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.954 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0865 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-08 | 1.0% | — |
| CVE-2020-0800 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-08 | 1.0% | — |
| CVE-2020-0797 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0800, CVE-2020-08 | 1.0% | — |
| CVE-2017-5068 | HIGH 7.5 | google chrome Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page. | 1.0% | — |
| CVE-2009-2048 | LOW 3.5 | cisco crs Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or H | 1.0% | — |
| CVE-2008-4542 | LOW 3.5 | cisco unity Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data store). | 1.0% | — |
| CVE-1999-0400 | MED 4.6 | linux linux_kernel Denial of service in Linux 2.2.0 running the ldd command on a core file. | 1.0% | — |
| CVE-2023-52798 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs radar event locking The ath11k active pdevs are protected by RCU but the DFS radar event handling code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a read-s | 1.0% | — |
| CVE-2023-42505 | MED 4.3 | apache superset An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0. | 1.0% | — |
| CVE-2023-36436 | HIGH 7.8 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-41746 | CRIT 9.1 | trendmicro apex_one A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to l | 1.0% | — |
| CVE-2022-28670 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 1.0% | — |
| CVE-2021-38633 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2013-2852 | MED 6.9 | canonical ubuntu_linux Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format strin | 1.0% | — |
| CVE-2025-21395 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-49056 | HIGH 7.3 | microsoft airlift_microsoft_com Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2024-36264 | CRIT 9.8 | apache submarine ** UNSUPPORTED WHEN ASSIGNED ** Improper Authentication vulnerability in Apache Submarine Commons Utils. If the user doesn't explicitly set `submarine.auth.default.secret`, a default value will be used. This issue affects Apache Submarine Commons Utils: fro | 1.0% | — |
| CVE-2023-36788 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-31685 | CRIT 9.8 | vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | 1.0% | — |
| CVE-2020-11583 | MED 6.1 | plesk obsidian A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter. | 1.0% | — |
| CVE-2019-6604 | MED 6.8 | f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.5.8, 11.6.1-11.6.3, 12.1.0-12.1.3.6, 13.0.0-13.1.1.1, and 14.0.0-14.0.0.2, under certain conditions, hardware systems with a High-Speed Bridge and using non-default Layer 2 forwarding configurations may experience a lockup of the High-Speed | 1.0% | — |
| CVE-2019-6594 | MED 5.9 | f5 big-ip_access_policy_manager On BIG-IP 11.5.1-11.6.3.2, 12.1.3.4-12.1.3.7, 13.0.0 HF1-13.1.1.1, and 14.0.0-14.0.0.2, Multi-Path TCP (MPTCP) does not protect against multiple zero length DATA_FINs in the reassembly queue, which can lead to an infinite loop in some circumstances. | 1.0% | — |
| CVE-2017-0626 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the Qualcomm crypto engine driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without expli | 1.0% | — |
| CVE-2017-0624 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user | 1.0% | — |
| CVE-2014-9870 | HIGH 7.8 | google android The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, a | 1.0% | — |