57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-26184 | MED 6.8 | microsoft windows_10_21h2 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2023-36557 | HIGH 7.8 | microsoft windows_10_1507 PrintHTML API Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-20080 | HIGH 8.6 | cisco ios A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation | 1.0% | — |
| CVE-2020-3549 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due | 1.0% | — |
| CVE-2020-0707 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2020-0704 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Wireless Network Manager Elevati | 1.0% | — |
| CVE-2014-3302 | MED 5.8 | cisco webex_meetings_server user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. | 1.0% | — |
| CVE-2002-1106 | HIGH 7.5 | cisco vpn_client Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks. | 1.0% | — |
| CVE-2025-29802 | HIGH 7.3 | microsoft visual_studio_2022 Improper access control in Visual Studio allows an authorized attacker to elevate privileges locally. | 0.9% | — |
| CVE-2024-38249 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-26168 | MED 6.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2023-49734 | HIGH 7.7 | apache superset An authenticated Gamma user has the ability to create a dashboard and add charts to it, this user would automatically become one of the owners of the charts allowing him to incorrectly have write permissions to these charts.This issue affects Apache Superset: | 0.9% | — |
| CVE-2023-20250 | MED 6.5 | cisco rv110w_firmware A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to improper vali | 0.9% | — |
| CVE-2022-20942 | MED 6.5 | cisco asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attack | 0.9% | — |
| CVE-2021-41361 | MED 5.4 | microsoft windows_server_2016 Active Directory Federation Server Spoofing Vulnerability | 0.9% | — |
| CVE-2021-41354 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 0.9% | — |
| CVE-2021-41353 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | 0.9% | — |
| CVE-2021-23039 | HIGH 7.5 | f5 big-ip_access_policy_manager On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3, 14.1.x before 14.1.2.8, and all versions of 13.1.x and 12.1.x, when IPSec is configured on a BIG-IP system, undisclosed requests from an authorized remote (IPSec) peer, which already has a negotiated Sec | 0.9% | — |
| CVE-2021-23035 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 14.1.x before 14.1.4.4, when an HTTP profile is configured on a virtual server, after a specific sequence of packets, chunked responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of | 0.9% | — |
| CVE-2021-23034 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.x before 16.1.0 and 15.1.x before 15.1.3.1, when a DNS profile using a DNS cache resolver is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) process to terminate. Note: Software versi | 0.9% | — |
| CVE-2021-0282 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS devices with Multipath or add-path feature enabled, processing a specific BGP UPDATE can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this UPDATE m | 0.9% | — |
| CVE-2020-1000 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1003, CVE-2020-1027. | 0.9% | — |
| CVE-2020-0985 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996. | 0.9% | — |
| CVE-2019-5006 | MED 5.5 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing. | 0.9% | — |
| CVE-2017-2317 | HIGH 8.6 | juniper northstar_controller A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading t | 0.9% | — |