57.961 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.961 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-26935 | MED 6.5 | microsoft windows_10 Windows WLAN AutoConfig Service Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-22310 | MED 6.5 | ibm websphere_application_server IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: | 1.0% | — |
| CVE-2022-20752 | MED 5.3 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This | 1.0% | — |
| CVE-2020-5406 | MED 6.5 | vmware tanzu_application_service_for_vms VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database usernam | 1.0% | — |
| CVE-2020-26072 | HIGH 8.7 | cisco iot_field_network_director A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the | 1.0% | — |
| CVE-2018-0390 | MED 6.1 | cisco webex_meetings A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab | 1.0% | — |
| CVE-2017-8577 | HIGH 7.0 | microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |
| CVE-2016-1394 | HIGH 8.6 | cisco firesight_system_software Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238. | 1.0% | — |
| CVE-2026-35337 | HIGH 8.8 | apache storm Deserialization of Untrusted Data vulnerability in Apache Storm. Versions Affected: before 2.8.6. Description: When processing topology credentials submitted via the Nimbus Thrift API, Storm deserializes the base64-encoded TGT blob using ObjectInputStream.r | 1.0% | — |
| CVE-2026-25185 | MED 5.3 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2025-64676 | HIGH 7.2 | microsoft purview '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-43496 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-3244 | MED 5.3 | cisco staros A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is du | 1.0% | — |
| CVE-2020-12393 | HIGH 7.8 | mozilla firefox The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in comman | 1.0% | — |
| CVE-2019-2390 | HIGH 8.2 | mongodb mongodb An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server | 1.0% | — |
| CVE-2019-15988 | MED 5.3 | cisco email_security_appliance_firmware A vulnerability in the antispam protection mechanisms of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass the URL reputation filters on an affected device. The vulnerability is due to ins | 1.0% | — |
| CVE-2017-8702 | HIGH 7.0 | microsoft windows_10 Windows Error Reporting (WER) in Microsoft Windows 10 Gold, 1511, and 1607, and Windows Server 2016 allows an attacker to gain greater access to sensitive information and system functionality, due to the way that WER handles and executes files, aka "Windows El | 1.0% | — |
| CVE-2015-4077 | LOW 2.1 | fortinet forticlient The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call. | 1.0% | — |
| CVE-2006-3593 | MED 4.0 | cisco unified_callmanager The command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to overwrite arbitrary files by redirecting a command's output to a file or folder, aka bug CSCse31704. | 1.0% | — |
| CVE-2026-55005 | HIGH 8.8 | microsoft exchange_server Heap-based buffer overflow in Microsoft Exchange Server allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-2008 | HIGH 8.2 | linux linux_kernel A flaw was found in the Linux kernel's udmabuf device driver, within a fault handler. This issue occurs due to the lack of proper validation of user-supplied data, which can result in memory access past the end of an array. This may allow an attacker to escala | 1.0% | — |
| CVE-2022-24765 | MED 6.0 | apple xcode Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted parties could create the folder `C:\.git`, w | 1.0% | — |
| CVE-2022-24122 | HIGH 7.8 | fedoraproject fedora kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace. | 1.0% | — |
| CVE-2022-22982 | HIGH 7.5 | vmware cloud_foundation The vCenter Server contains a server-side request forgery (SSRF) vulnerability. A malicious actor with network access to 443 on the vCenter Server may exploit this issue by accessing a URL request outside of vCenter Server or accessing an internal service. | 1.0% | — |
| CVE-2021-31170 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 1.0% | — |