57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.924 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-59249 | HIGH 8.8 | microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-5257 | LOW 3.5 | whitehsbg jndiexploit A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFileRequest of the file src/main/java/com/feihong/ldap/HTTPServer.java. The manipulation leads to path traversal. | 0.8% | — |
| CVE-2023-48784 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI a | 0.8% | — |
| CVE-2023-29353 | MED 5.5 | microsoft sysinternals Sysinternals Process Monitor for Windows Denial of Service Vulnerability | 0.8% | — |
| CVE-2021-27195 | MED 5.9 | netop vision_pro Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | 0.8% | — |
| CVE-2021-22047 | MED 5.3 | vmware spring_data_rest In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c | 0.8% | — |
| CVE-2020-1273 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0.8% | — |
| CVE-2020-1162 | HIGH 7.8 | microsoft windows_10 An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vul | 0.8% | — |
| CVE-2016-8475 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the HTC input driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: An | 0.8% | — |
| CVE-2016-8474 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr | 0.8% | — |
| CVE-2016-8473 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr | 0.8% | — |
| CVE-2016-8469 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Andro | 0.8% | — |
| CVE-2015-3006 | MED 6.5 | juniper junos On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys or self-signed SSL/TLS certificates. Entropy increases after t | 0.8% | — |
| CVE-2000-0227 | LOW 2.1 | linux linux_kernel The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which allows local users to cause a denial of service by requesting a large number of sockets. | 0.8% | — |
| CVE-2026-81377 | MED 6.5 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. | 0.8% | — |
| CVE-2024-5494 | HIGH 8.8 | fedoraproject fedora Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | 0.8% | — |
| CVE-2024-27393 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: xen-netfront: Add missing skb_mark_for_recycle Notice that skb_mark_for_recycle() is introduced later than fixes tag in commit 6a5bcd84e886 ("page_pool: Allow drivers to hint on SKB recyclin | 0.8% | — |
| CVE-2022-46872 | HIGH 8.6 | mozilla firefox An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability aff | 0.8% | — |
| CVE-2022-45461 | HIGH 7.5 | veritas netbackup The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root. | 0.8% | — |
| CVE-2022-40677 | HIGH 7.2 | fortinet fortinac A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allow | 0.8% | — |
| CVE-2022-21865 | HIGH 7.0 | microsoft windows_10 Connected Devices Platform Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-21864 | HIGH 7.0 | microsoft windows_10 Windows UI Immersive Server API Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-21860 | HIGH 7.0 | microsoft windows_10 Windows AppContracts API Server Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1709 | HIGH 7.0 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-3301 | MED 4.4 | cisco secure_firewall_management_center Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulne | 0.8% | — |