57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49029 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-49028 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-49027 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2024-49021 | HIGH 7.8 | microsoft sql_server_2016 Microsoft SQL Server Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44687 | HIGH 7.8 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44668 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-44667 | HIGH 7.8 | microsoft windows_10 Windows Media Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-26791 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26789 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-22953 | MED 6.5 | vmware vmware_hcx VMware HCX update addresses an information disclosure vulnerability. A malicious actor with network user access to the VMware HCX appliance may be able to gain access to sensitive information. | 0.8% | — |
| CVE-2021-47397 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: sctp: break out if skb_header_pointer returns NULL in sctp_rcv_ootb We should always check if skb_header_pointer's return is NULL before using it, otherwise it may cause null-ptr-deref, as s | 0.8% | — |
| CVE-2021-43243 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-43235 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-43227 | MED 5.5 | microsoft windows_10 Storage Spaces Controller Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-3864 | HIGH 7.0 | debian debian_linux A flaw was found in the way the dumpable flag setting was handled when certain SUID binaries executed its descendants. The prerequisite is a SUID binary that sets real UID equal to effective UID, and real GID equal to effective GID. The descendant will then ha | 0.8% | — |
| CVE-2021-28317 | MED 5.5 | microsoft windows_10 Microsoft Windows Codecs Library Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-23055 | MED 6.5 | f5 nginx_ingress_controller On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evalua | 0.8% | — |
| CVE-2017-3877 | MED 6.5 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More | 0.8% | — |
| CVE-2010-4685 | MED 4.0 | cisco ios Cisco IOS before 15.0(1)XA1 does not clear the public key cache upon a change to a certificate map, which allows remote authenticated users to bypass a certificate ban by connecting with a banned certificate that had previously been valid, aka Bug ID CSCta7903 | 0.8% | — |
| CVE-2022-30162 | MED 5.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2020-12819 | MED 5.4 | fortinet fortios A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 and earlier may allow a remote attacker with valid SSL VPN credentials to crash the SSL VPN daemon by sending a | 0.8% | — |
| CVE-2019-6695 | CRIT 9.8 | fortinet fortimanager Lack of root file system integrity checking in Fortinet FortiManager VM application images of 6.2.0, 6.0.6 and below may allow an attacker to implant third-party programs by recreating the image through specific methods. | 0.8% | — |
| CVE-2016-1090 | HIGH 7.8 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege | 0.8% | — |
| CVE-2016-1087 | HIGH 7.8 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege | 0.8% | — |
| CVE-2026-30898 | HIGH 8.8 | apache airflow An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own | 0.8% | — |