IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-1703 HIGH 7.8 microsoft windows_10 Windows Event Logging Service Elevation of Privilege Vulnerability 0.8%
CVE-2021-1650 HIGH 7.8 microsoft windows_10 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability 0.8%
CVE-2017-7374 HIGH 7.8 linux linux_kernel Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing 0.8%
CVE-2025-27484 HIGH 7.5 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2024-43465 HIGH 7.8 microsoft 365_apps Microsoft Excel Elevation of Privilege Vulnerability 0.8%
CVE-2024-30362 HIGH 7.8 foxit pdf_editor Foxit PDF Reader PDF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability 0.8%
CVE-2022-26806 HIGH 7.8 microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability 0.8%
CVE-2022-20867 MED 5.4 cisco asyncos A vulnerability in web-based management interface of the of Cisco Email Security Appliance and Cisco Secure Email and Web Manager could allow an authenticated, remote attacker to conduct SQL injection attacks as root on an affected system. The attacker must ha 0.8%
CVE-2025-65995 MED 6.5 apache airflow When a DAG failed during parsing, Airflow’s error-reporting in the UI could include the full kwargs passed to the operators. If those kwargs contained sensitive values (such as secrets), they might be exposed in the UI tracebacks to authenticated users who had 0.8%
CVE-2024-21363 HIGH 7.8 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 0.8%
CVE-2022-22779 LOW 3.7 keybase keybase The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user. This can occur if the receiving user switches to a non-chat feature and places the host in a sleep state before the sending user expl 0.8%
CVE-2021-31961 MED 6.1 microsoft windows_10 Windows InstallService Elevation of Privilege Vulnerability 0.8%
CVE-2020-3356 MED 6.1 cisco data_center_network_manager A vulnerability in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insuff 0.8%
CVE-2020-3313 MED 6.1 cisco secure_firewall_management_center A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the FMC Software. The vulne 0.8%
CVE-2020-3282 MED 6.1 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could all 0.8%
CVE-2020-3192 MED 6.1 cisco prime_collaboration_provisioning A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerabili 0.8%
CVE-2020-3159 MED 6.1 cisco finesse A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected software. The vulnerabili 0.8%
CVE-2020-26081 MED 6.1 cisco iot_field_network_director Multiple vulnerabilities in the web UI of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against users on an affected system. The vulnerabilities are due to insufficient vali 0.8%
CVE-2020-12811 MED 6.1 fortinet fortianalyzer An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name fie 0.8%
CVE-2019-16024 MED 6.1 cisco crosswork_change_automation A vulnerability in the web-based management interface of Cisco Crosswork Change Automation could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system 0.8%
CVE-2019-16015 MED 6.1 cisco data_center_analytics_framework A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affect 0.8%
CVE-2019-15994 MED 6.1 cisco stealthwatch_enterprise A vulnerability in the web-based management interface of Cisco Stealthwatch Enterprise could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. Th 0.8%
CVE-2019-15973 MED 6.1 cisco industrial_network_director A vulnerability in the web-based management interface of Cisco Industrial Network Director (IND) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected application. The vuln 0.8%
CVE-2019-15969 MED 6.1 cisco web_security_appliance A vulnerability in the web-based management interface of Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface of an affected device. The vulnerability i 0.8%
CVE-2019-12718 MED 6.1 cisco sf200-24_firmware A vulnerability in the web-based interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to 0.8%