57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21751 | MED 6.5 | microsoft azure_devops_server Azure DevOps Server Spoofing Vulnerability | 1.0% | — |
| CVE-2022-35806 | HIGH 7.8 | microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-31169 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31168 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-31165 | HIGH 7.8 | microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-15706 | MED 6.4 | canonical ubuntu_linux GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restri | 1.0% | — |
| CVE-2020-1082 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vul | 1.0% | — |
| CVE-2020-0804 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Network Connections Service handles objects in memory, aka 'Windows Network Connections Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0778, CVE-2020 | 1.0% | — |
| CVE-2019-1940 | MED 5.9 | cisco industrial_network_director A vulnerability in the Web Services Management Agent (WSMA) feature of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid X.509 certificate. The vulnerabil | 1.0% | — |
| CVE-2023-39197 | MED 4.0 | fedoraproject fedora An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol. | 1.0% | — |
| CVE-2022-34301 | MED 6.7 | kidan cryptopro_securedisk_for_bitlocker A flaw was found in CryptoPro Secure Disk bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replac | 1.0% | — |
| CVE-2022-27512 | MED 5.3 | citrix application_delivery_management Temporary disruption of the ADM license service. The impact of this includes preventing new licenses from being issued or renewed by Citrix ADM. | 1.0% | — |
| CVE-2022-23020 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.1.x before 16.1.2, when the 'Respond on Error' setting is enabled on the Request Logging profile and configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versi | 1.0% | — |
| CVE-2021-21992 | MED 6.5 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit t | 1.0% | — |
| CVE-2020-29011 | HIGH 8.8 | fortinet fortisandbox Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an authenticated attacker to execute unauthorized code on the underlying SQL interpreter via spe | 1.0% | — |
| CVE-2020-17068 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-17037 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-16916 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when Windows improperly handles COM object creation. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges.</p> <p>To exploit this vulnerability, an attacker | 1.0% | — |
| CVE-2020-1549 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows CDP User Components improperly handle memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted app | 1.0% | — |
| CVE-2020-1486 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 1.0% | — |
| CVE-2017-5329 | HIGH 7.8 | paloaltonetworks terminal_services_agent Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger an out-of-bounds write operation. | 1.0% | — |
| CVE-2017-0427 | HIGH 7.8 | google android An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromi | 1.0% | — |
| CVE-2014-3347 | MED 5.4 | cisco 1801_integrated_service_router Cisco IOS 15.1(4)M2 on Cisco 1800 ISR devices, when the ISDN Basic Rate Interface is enabled, allows remote attackers to cause a denial of service (device hang) by leveraging knowledge of the ISDN phone number to trigger an interrupt timer collision during ent | 1.0% | — |
| CVE-2026-77493 | CRIT 9.8 | microsoft windows_10_1607 Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-70296 | CRIT 9.8 | microsoft windows_10_1607 Out-of-bounds write in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | 1.0% | — |