57.962 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.962 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1602 | HIGH 7.1 | juniper junos When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may remotely take over the code ex | 0.8% | — |
| CVE-2020-0942 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 0.8% | — |
| CVE-2020-0936 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2017-7735 | MED 5.4 | fortinet fortios A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups. | 0.8% | — |
| CVE-2017-7734 | MED 5.4 | fortinet fortios A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions. | 0.8% | — |
| CVE-2017-6707 | HIGH 8.2 | cisco staros A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker | 0.8% | — |
| CVE-2016-8460 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user p | 0.8% | — |
| CVE-2015-6295 | MED 4.8 | cisco nx-os Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause a denial of service (CPU consumption or control-plane instability) or trigger unintended traffic forwarding via a Layer 2 packet with a reserved VLAN number, a | 0.8% | — |
| CVE-2026-23231 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix use-after-free in nf_tables_addchain() nf_tables_addchain() publishes the chain to table->chains via list_add_tail_rcu() (in nft_chain_add()) before registering hoo | 0.8% | — |
| CVE-2025-55326 | HIGH 7.5 | microsoft windows_10_1809 Use after free in Connected Devices Platform Service (Cdpsvc) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-24783 | HIGH 7.5 | apache cocoon ** UNSUPPORTED WHEN ASSIGNED ** Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) vulnerability in Apache Cocoon. This issue affects Apache Cocoon: all versions. When a continuation is created, it gets a random identifier. Because the random | 0.8% | — |
| CVE-2024-38587 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: speakup: Fix sizeof() vs ARRAY_SIZE() bug The "buf" pointer is an array of u16 values. This code should be using ARRAY_SIZE() (which is 256) instead of sizeof() (which is 512), otherwise it | 0.8% | — |
| CVE-2024-38183 | CRIT 9.8 | microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2024-29070 | CRIT 9.1 | apache streampark On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authentication credential. "Authorization" can still initiate requests and access data even af | 0.8% | — |
| CVE-2023-25012 | MED 4.6 | linux linux_kernel The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long. | 0.8% | — |
| CVE-2022-23297 | MED 5.5 | microsoft windows_10 Windows NT Lan Manager Datagram Receiver Driver Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-23252 | MED 5.5 | microsoft 365_apps Microsoft Office Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-21985 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-41780 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader before 11.1 and PDF Editor before 11.1, and PhantomPDF before 10.1.6, allow attackers to trigger a use-after-free and execute arbitrary code because JavaScript is mishandled. | 0.8% | — |
| CVE-2020-27815 | HIGH 7.8 | debian debian_linux A flaw was found in the JFS filesystem code in the Linux Kernel which allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to | 0.8% | — |
| CVE-2020-24447 | HIGH 7.0 | adobe lightroom Adobe Lightroom Classic version 10.0 (and earlier) for Windows is affected by an uncontrolled search path vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in th | 0.8% | — |
| CVE-2020-1306 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Runtime improperly handles objects in memory, aka 'Windows Runtime Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1231, CVE-2020-1233, CVE-2020-1235, CVE-2020-1265, CVE | 0.8% | — |
| CVE-2020-0944 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 0.8% | — |
| CVE-2020-0919 | HIGH 7.8 | microsoft windows_app An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0793 | HIGH 7.8 | microsoft visual_studio_2015 An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. | 0.8% | — |