IT
57.925 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.925 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-24556 HIGH 7.8 trendmicro apex_one A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulate 0.8%
CVE-2019-12400 MED 5.5 apache santuario_xml_security_for_java In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread 0.8%
CVE-2001-0316 MED 4.6 linux linux_kernel Linux kernel 2.4 and 2.2 allows local users to read kernel memory and possibly gain privileges via a negative argument to the sysctl call. 0.8%
CVE-2026-64609 CRIT 9.1 apache fory Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that d 0.8%
CVE-2024-30102 HIGH 7.3 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.8%
CVE-2022-48666 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: scsi: core: Fix a use-after-free There are two .exit_cmd_priv implementations. Both implementations use resources associated with the SCSI host. Make sure that these resources are still avai 0.8%
CVE-2022-30135 HIGH 7.8 microsoft windows_7 Windows Media Center Elevation of Privilege Vulnerability 0.8%
CVE-2021-47245 HIGH 8.2 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: Fix out of bounds when parsing TCP options The TCP option parser in synproxy (synproxy_parse_options) could read one byte out of bounds. When the length is 1, the execut 0.8%
CVE-2021-38662 MED 5.5 microsoft windows_10 Windows Fast FAT File System Driver Information Disclosure Vulnerability 0.8%
CVE-2020-1146 MED 6.6 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Microsoft Store Runtime improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially craf 0.8%
CVE-2020-1130 MED 6.6 microsoft visual_studio <p>An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector improperly handles data operations. An attacker who successfully exploited this vulnerability could run processes in an elevated context.</p> <p>An attacker could exp 0.8%
CVE-2019-7960 HIGH 7.8 adobe animate_cc Adobe Animate CC versions 19.2.1 and earlier have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation. 0.8%
CVE-2017-4926 MED 5.4 vmware vcenter_server VMware vCenter Server (6.5 prior to 6.5 U1) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker with VC user privileges can inject malicious java-scripts which will get executed when other VC users access the page. 0.8%
CVE-2026-62902 MED 6.5 microsoft .net Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information over a network. 0.8%
CVE-2026-57100 CRIT 9.9 microsoft entra_provisioning_service Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-54998 HIGH 8.8 microsoft exchange_online Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-50444 HIGH 8.8 microsoft windows_10_1607 Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-50360 HIGH 8.8 microsoft windows_10_21h2 Incorrect implementation of authentication algorithm in Windows SMB Server allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-47647 CRIT 9.9 microsoft dynamics_365 Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-45499 CRIT 9.9 microsoft azure_openai Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-32157 HIGH 8.8 microsoft remote_desktop_client Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-61623 MED 6.5 apache ofbiz Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users are recommended to upgrade to version 24.09.03, which fixes the issue. 0.8%
CVE-2025-34193 CRIT 9.8 vasion virtual_appliance_application Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLaunche 0.8%
CVE-2025-29815 HIGH 7.6 microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. 0.8%
CVE-2025-21296 HIGH 7.5 microsoft windows_10_1507 BranchCache Remote Code Execution Vulnerability 0.8%