IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-2318 MED 6.5 juniper northstar_controller A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges. 1.0%
CVE-2026-47295 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.0%
CVE-2026-45495 HIGH 8.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.0%
CVE-2023-38522 HIGH 7.5 apache traffic_server Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards malformed requests to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue 1.0%
CVE-2023-36593 HIGH 7.8 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%
CVE-2023-21796 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 1.0%
CVE-2023-21775 HIGH 8.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.0%
CVE-2021-47348 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Avoid HDCP over-read and corruption Instead of reading the desired 5 bytes of the actual target field, the code was reading 8. This could result in a corrupted value if the 1.0%
CVE-2021-40128 MED 5.3 cisco webex_meetings A vulnerability in the account activation feature of Cisco Webex Meetings could allow an unauthenticated, remote attacker to send an account activation email with an activation link that points to an arbitrary domain. This vulnerability is due to insufficient 1.0%
CVE-2009-3621 MED 5.5 canonical ubuntu_linux net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series o 1.0%
CVE-2026-34401 MED 6.5 microsoft xml_notepad XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. 1.0%
CVE-2025-58729 MED 6.5 microsoft windows_10_1507 Improper validation of specified type of input in Windows Local Session Manager (LSM) allows an authorized attacker to deny service over a network. 1.0%
CVE-2025-27727 HIGH 7.8 microsoft windows_10_1507 Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally. 1.0%
CVE-2025-24070 HIGH 7.0 microsoft asp.net_core Weak authentication in ASP.NET Core & Visual Studio allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2023-36896 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1.0%
CVE-2023-35372 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 1.0%
CVE-2023-35371 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 1.0%
CVE-2022-37991 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2022-37988 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2020-1079 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete dat 1.0%
CVE-2019-18683 HIGH 7.0 broadcom fabric_operating_system An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are 1.0%
CVE-2018-0196 MED 4.9 cisco ios_xe A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to write arbitrary files to the operating system of an affected device. The vulnerability is due to insufficient input validation of 1.0%
CVE-2013-3301 HIGH 7.2 linux linux_kernel The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the 1.0%
CVE-2013-2408 MED 4.3 oracle peoplesoft_products Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via vectors related to PIA Core Technology and use of Internet Explorer 6. 1.0%
CVE-2026-43865 HIGH 8.1 apache camel Deserialization of Untrusted Data vulnerability in Apache Camel Hazelcast component. The camel-hazelcast component creates and manages Hazelcast instances using a default configuration that applies no Java deserialization filter. When Camel builds the Hazelca 1.0%