IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-15775 HIGH 7.8 xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000259aa4." 0.8%
CVE-2017-15773 HIGH 7.8 xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285d79." 0.8%
CVE-2017-15772 HIGH 7.8 xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285e9 0.8%
CVE-2015-0707 LOW 3.5 cisco firesight_system_software Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Center allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCus85425. 0.8%
CVE-2013-5541 LOW 3.5 cisco identity_services_engine Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495. 0.8%
CVE-2013-1244 LOW 3.5 cisco webex_social Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199. 0.8%
CVE-2026-69875 HIGH 8.0 microsoft windows_10_1809 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-69505 HIGH 8.0 microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-69503 HIGH 8.0 microsoft windows_10_1809 Stack-based buffer overflow in Windows USB Driver allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-69461 HIGH 8.8 microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-47162 HIGH 8.4 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 0.8%
CVE-2024-39462 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: clk: bcm: dvp: Assign ->num before accessing ->hws Commit f316cdff8d67 ("clk: Annotate struct clk_hw_onecell_data with __counted_by") annotated the hws member of 'struct clk_hw_onecell_data' 0.8%
CVE-2022-45934 HIGH 7.8 debian debian_linux An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. 0.8%
CVE-2021-47064 MED 5.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mt76: fix potential DMA mapping leak With buf uninitialized in mt76_dma_tx_queue_skb_raw, its field skip_unmap could potentially inherit a non-zero value from stack garbage. If this happens, 0.8%
CVE-2021-26096 MED 6.4 fortinet fortisandbox Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate memory and alter its content by means of specifically crafted command line arguments. 0.8%
CVE-2021-23046 MED 4.9 f5 big-ip_access_policy_manager On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs. Note: Software versions which have reache 0.8%
CVE-2020-15933 MED 5.3 fortinet fortimail A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via 0.8%
CVE-2020-0935 MED 5.5 microsoft onedrive An elevation of privilege vulnerability exists when the OneDrive for Windows Desktop application improperly handles symbolic links, aka 'OneDrive for Windows Elevation of Privilege Vulnerability'. 0.8%
CVE-2019-1835 MED 4.4 cisco aironet_access_point_firmware A vulnerability in the CLI of Cisco Aironet Access Points (APs) could allow an authenticated, local attacker to access sensitive information stored in an AP. The vulnerability is due to improper sanitization of user-supplied input in specific CLI commands. An 0.8%
CVE-2010-4255 MED 6.1 citrix xen The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause 0.8%
CVE-2026-65905 CRIT 9.8 apache tomcat Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that 0.8%
CVE-2026-40375 MED 6.5 microsoft dynamics_365_business_central_2024 Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. 0.8%
CVE-2025-25001 MED 4.3 microsoft edge Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.8%
CVE-2024-49031 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0.8%
CVE-2024-49030 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.8%