57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-29367 | HIGH 7.8 | microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29366 | HIGH 7.8 | microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29365 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-45052 | HIGH 8.8 | axiell iguana A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server. | 0.7% | — |
| CVE-2022-20810 | MED 6.5 | cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to insufficient | 0.7% | — |
| CVE-2021-43389 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. | 0.7% | — |
| CVE-2012-4131 | MED 4.6 | cisco nx-os Directory traversal vulnerability in tar in Cisco NX-OS allows local users to access arbitrary files via crafted command-line arguments, aka Bug IDs CSCty07157, CSCty07159, CSCty07162, and CSCty07164. | 0.7% | — |
| CVE-2026-57985 | HIGH 7.6 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-33105 | CRIT 10.0 | microsoft azure_kubernetes_service Improper authorization in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-48912 | MED 6.5 | apache superset An authenticated malicious actor using specially crafted requests could bypass row level security configuration by injecting SQL into 'sqlExpression' fields. This allowed the execution of sub-queries to evade parsing defenses ultimately granting unauthorized a | 0.7% | — |
| CVE-2025-21213 | MED 4.6 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-20721 | MED 5.5 | adobe acrobat Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current | 0.7% | — |
| CVE-2023-35331 | MED 6.5 | microsoft windows_server_2012 Windows Local Security Authority (LSA) Denial of Service Vulnerability | 0.7% | — |
| CVE-2023-21774 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-21772 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-20174 | MED 4.9 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To e | 0.7% | — |
| CVE-2023-0458 | MED 5.3 | debian debian_linux A speculative pointer dereference problem exists in the Linux Kernel on the do_prlimit() function. The resource argument value is controlled and is used in pointer arithmetic for the 'rlim' variable and can be used to leak the contents. We recommend upgrading | 0.7% | — |
| CVE-2022-35241 | MED 6.5 | f5 nginx_instance_manager In versions 2.x before 2.3.1 and all versions of 1.x, when NGINX Instance Manager is in use, undisclosed requests can cause an increase in disk resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0.7% | — |
| CVE-2022-34851 | MED 4.3 | f5 big-ip_access_policy_manager In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, and BIG-IQ Centralized Management all versions of 8.x, an authenticated attacker may cause iControl SOAP to become un | 0.7% | — |
| CVE-2022-20674 | MED 6.1 | cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul | 0.7% | — |
| CVE-2022-20673 | MED 6.1 | cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul | 0.7% | — |
| CVE-2022-20672 | MED 6.1 | cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul | 0.7% | — |
| CVE-2022-20671 | MED 6.1 | cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul | 0.7% | — |
| CVE-2022-20670 | MED 6.1 | cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul | 0.7% | — |
| CVE-2022-20669 | MED 6.1 | cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul | 0.7% | — |