57.872 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.872 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-7812 | HIGH 7.8 | kaoni ezhttptrans Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by reb | 0.7% | — |
| CVE-2020-7806 | HIGH 7.8 | tobesoft xplatform Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code execution. | 0.7% | — |
| CVE-2019-19167 | HIGH 7.8 | tobesoft nexacro Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution. | 0.7% | — |
| CVE-2013-6682 | MED 6.4 | cisco adaptive_security_appliance_software The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid ent | 0.7% | — |
| CVE-2026-70306 | CRIT 9.3 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2026-45249 | MED 6.1 | apache echarts A cross-site scripting (XSS) vulnerability exists in Apache ECharts in the Lines series tooltip rendering logic. This issue affects Apache ECharts: from before 6.1.0. In versions prior to 6.1.0, if both Lines series and tooltip are used, and no user-speci | 0.7% | — |
| CVE-2026-0227 | HIGH 7.5 | paloaltonetworks pan-os A vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to cause a denial of service (DoS) to the firewall. Repeated attempts to trigger this issue results in the firewall entering into maintenance mode. | 0.7% | — |
| CVE-2025-62222 | HIGH 8.8 | microsoft github_copilot_chat Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat Extension allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2025-46548 | MED 6.5 | akka akka_management If you enable Basic Authentication in Pekko Management using the Java DSL, the authenticator may not be properly applied. Users that rely on authentication instead of making sure the Management API ports are only available to trusted users are recommended to | 0.7% | — |
| CVE-2025-21416 | HIGH 8.5 | microsoft azure_virtual_desktop Missing authorization in Azure Virtual Desktop allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2024-40761 | MED 5.3 | apache answer Inadequate Encryption Strength vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. Using the MD5 value of a user's email to access Gravatar is insecure and can lead to the leakage of user email. The official recommendation is to | 0.7% | — |
| CVE-2023-23420 | HIGH 7.8 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-34744 | MED 4.9 | cisco business_220-16p-2g_firmware Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an attacker with Administrator privileges to access sensitive login credentials or reconfigure the passwords on the user account. For more information about these vulnera | 0.7% | — |
| CVE-2021-25247 | HIGH 7.8 | trendmicro housecall_for_home_networks A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the ma | 0.7% | — |
| CVE-2020-0632 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0630 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0629 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0626 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE- | 0.7% | — |
| CVE-2020-0620 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Cryptographic Services improperly handles files, aka 'Microsoft Cryptographic Services Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2017-12222 | MED 6.5 | cisco ios_xe A vulnerability in the wireless controller manager of Cisco IOS XE could allow an unauthenticated, adjacent attacker to cause a restart of the switch and result in a denial of service (DoS) condition. The vulnerability is due to insufficient input validation. | 0.7% | — |
| CVE-2016-6411 | HIGH 7.5 | cisco firesight_system_software Cisco Firepower Management Center and FireSIGHT System Software 6.0.1 mishandle comparisons between URLs and X.509 certificates, which allows remote attackers to bypass intended do-not-decrypt settings via a crafted URL, aka Bug ID CSCva50585. | 0.7% | — |
| CVE-2009-3888 | MED 4.9 | linux linux_kernel The do_mmap_pgoff function in mm/nommu.c in the Linux kernel before 2.6.31.6, when the CPU lacks a memory management unit, allows local users to cause a denial of service (OOPS) via an application that attempts to allocate a large amount of memory. | 0.7% | — |
| CVE-2026-40021 | MED 5.3 | apache log4net Apache Log4net's XmlLayout https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list and XmlLayoutSchemaLog4J https://logging.apache.org/log4net/manual/configuration/layouts.html#layout-list , in versions before 3.3.0, fail to sanitiz | 0.8% | — |
| CVE-2026-25903 | MED 6.6 | apache nifi Apache NiFi 1.1.0 through 2.7.2 are missing authorization when updating configuration properties on extension components that have specific Required Permissions based on the Restricted annotation. The Restricted annotation indicates additional privileges requi | 0.8% | — |
| CVE-2026-20834 | MED 4.6 | microsoft windows_10_1607 Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack. | 0.8% | — |