57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1010 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Block Level Backup Engine Service (wbengine) that allows file deletion in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system. An attacker could then | 1.0% | — |
| CVE-2020-0621 | MED 4.4 | microsoft windows_10 A security feature bypass vulnerability exists in Windows 10 when third party filters are called during a password update, aka 'Windows Security Feature Bypass Vulnerability'. | 1.0% | — |
| CVE-2017-8590 | HIGH 8.8 | microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to the way that the Windows C | 1.0% | — |
| CVE-2012-3336 | HIGH 8.8 | ibm infosphere_guardium IBM InfoSphere Guardium 8.0, 8.01, and 8.2 is vulnerable to SQL injection. A remote authenticated attacker could send specially-crafted SQL statements to multiple scripts, which could allow the attacker to view, add, modify or delete information in the back-en | 1.0% | — |
| CVE-2002-0499 | LOW 2.1 | linux linux_kernel The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generating an error, which could allow local users to force programs to perform inappropriate operations on the wrong directories. | 1.0% | — |
| CVE-2025-49717 | HIGH 8.5 | microsoft sql_server_2019 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2024-21374 | MED 5.0 | microsoft teams Microsoft Teams for Android Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-28513 | MED 5.9 | ibm mq IBM MQ 9.0 LTS, 9.1 LTS, 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.3 CD and IBM MQ Appliance 9.2 LTS, 9.3 LTS, 9.2 CD, and 9.2 LTS, under certain configurations, is vulnerable to a denial of service attack caused by an error processing messages. IBM X-Force ID: 250397 | 1.0% | — |
| CVE-2022-30306 | MED 6.6 | fortinet fortiweb A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted | 1.0% | — |
| CVE-2017-6161 | MED 5.3 | f5 big-ip_access_policy_manager In F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, GTM, Link Controller, PEM, WebAccelerator software version 12.0.0 - 12.1.2, 11.6.0 - 11.6.1, 11.4.0 - 11.5.4, 11.2.1, when ConfigSync is configured, attackers on adjacent networks may be able | 1.0% | — |
| CVE-2025-34195 | CRIT 9.8 | vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability during driver installation caused by unquoted program paths. The | 1.0% | — |
| CVE-2024-35161 | HIGH 7.5 | apache traffic_server Apache Traffic Server forwards malformed HTTP chunked trailer section to origin servers. This can be utilized for request smuggling and may also lead cache poisoning if the origin servers are vulnerable. This issue affects Apache Traffic Server: from 8.0.0 th | 1.0% | — |
| CVE-2023-20861 | MED 6.5 | vmware spring_framework In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition. | 1.0% | — |
| CVE-2022-30197 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 1.0% | — |
| CVE-2022-20819 | MED 6.5 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to obtain sensitive information from an affected device. This vulnerability exists because administrative privilege leve | 1.0% | — |
| CVE-2021-34772 | MED 4.7 | cisco orbital A vulnerability in the web-based management interface of Cisco Orbital could allow an unauthenticated, remote attacker to redirect users to a malicious webpage. This vulnerability is due to improper validation of URL paths in the web-based management interface | 1.0% | — |
| CVE-2017-7109 | MED 6.1 | apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" compone | 1.0% | — |
| CVE-2026-50646 | HIGH 7.8 | microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-65037 | CRIT 10.0 | microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-48817 | HIGH 8.8 | microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2025-29831 | HIGH 7.5 | microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2023-6240 | MED 6.5 | linux linux_kernel A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key. | 1.0% | — |
| CVE-2023-46227 | HIGH 7.5 | apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [ | 1.0% | — |
| CVE-2023-35394 | MED 4.6 | microsoft azure_hdinsight Azure HDInsight Jupyter Notebook Spoofing Vulnerability | 1.0% | — |
| CVE-2022-38037 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |