57.811 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.811 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1363 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Picker Platform improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Picker Platform Elevation of Privilege Vu | 0.7% | — |
| CVE-2020-1352 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows USO Core Worker improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows USO Core Worker Elevation of Privilege Vu | 0.7% | — |
| CVE-2019-18660 | MED 4.7 | canonical ubuntu_linux The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c. | 0.7% | — |
| CVE-2024-44984 | CRIT 10.0 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: bnxt_en: Fix double DMA unmapping for XDP_REDIRECT Remove the dma_unmap_page_attrs() call in the driver's XDP_REDIRECT code path. This should have been removed when we let the page pool han | 0.7% | — |
| CVE-2024-27182 | MED 4.9 | apache linkis In Apache Linkis <= 1.5.0, Arbitrary file deletion in Basic management services on A user with an administrator account could delete any file accessible by the Linkis system user . Users are recommended to upgrade to version 1.6.0, which fixes this issue. | 0.7% | — |
| CVE-2023-21805 | HIGH 7.8 | microsoft windows_10 Windows MSHTML Platform Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-20085 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected dev | 0.7% | — |
| CVE-2022-23805 | HIGH 7.1 | trendmicro worry-free_business_security A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server could allow a local attacker to send garbage data to a specific named pipe and crash the server. Please note: an attacker must first obtain th | 0.7% | — |
| CVE-2011-3274 | MED 6.1 | cisco ios Unspecified vulnerability in Cisco IOS 12.2SRE before 12.2(33)SRE4, 15.0, and 15.1, and IOS XE 2.1.x through 3.3.x, when an MPLS domain is configured, allows remote attackers to cause a denial of service (device crash) via a crafted IPv6 packet, related to an | 0.7% | — |
| CVE-2026-56140 | CRIT 9.8 | apache camel Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-specific HeaderFilterStrategy, Sns2HeaderFilterStrategy. Like the sibling Sqs2HeaderFilterStrategy, it originall | 0.7% | — |
| CVE-2024-31979 | MED 4.3 | apache streampipes Server-Side Request Forgery (SSRF) vulnerability in Apache StreamPipes during installation process of pipeline elements. Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements. These endpoints we | 0.7% | — |
| CVE-2024-30039 | MED 5.5 | microsoft windows_10_1507 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.7% | — |
| CVE-2023-52618 | MED 5.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: block/rnbd-srv: Check for unlikely string overflow Since "dev_search_path" can technically be as large as PATH_MAX, there was a risk of truncation when copying it and a second string into "f | 0.7% | — |
| CVE-2023-47747 | MED 5.3 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 272646. | 0.7% | — |
| CVE-2023-47746 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 272644. | 0.7% | — |
| CVE-2023-47158 | MED 5.3 | ibm db2 IBM DB2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1 and 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270750. | 0.7% | — |
| CVE-2023-47141 | MED 5.3 | ibm db2 IIBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 could allow an authenticated user with CONNECT privileges to cause a denial of service using a specially crafted query. IBM X-Force ID: 270264. | 0.7% | — |
| CVE-2022-20740 | MED 6.1 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting attack. This vulnerability is due to improper validation of user-supplie | 0.7% | — |
| CVE-2021-47162 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: skb_linearize the head skb when reassembling msgs It's not a good idea to append the frag skb to a skb's frag_list if the frag_list already has skbs from elsewhere, such as this skb wa | 0.7% | — |
| CVE-2021-34706 | MED 6.4 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access sensitive information or conduct a server-side request forgery (SSRF) attack through an affected device. This | 0.7% | — |
| CVE-2020-3447 | MED 5.5 | cisco content_security_management_appliance A vulnerability in the CLI of Cisco AsyncOS for Cisco Email Security Appliance (ESA) and Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, remote attacker to access sensitive information on an affected device. Th | 0.7% | — |
| CVE-2020-1553 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit this vulnerabilit | 0.7% | — |
| CVE-2020-1490 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker | 0.7% | — |
| CVE-2020-1484 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted a | 0.7% | — |
| CVE-2020-1463 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the SharedStream Library handles objects in memory, aka 'Windows SharedStream Library Elevation of Privilege Vulnerability'. | 0.7% | — |