57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-12705 | MED 6.1 | cisco telepresence_video_communication_server A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-ba | 0.8% | — |
| CVE-2018-0465 | MED 6.1 | cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected system. The | 0.8% | — |
| CVE-2016-6401 | MED 5.3 | cisco carrier_routing_system Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494. | 0.8% | — |
| CVE-2012-2421 | LOW 1.8 | intuit quickbooks Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read | 0.8% | — |
| CVE-2010-3850 | LOW 2.1 | canonical ubuntu_linux The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call. | 0.8% | — |
| CVE-2004-0497 | LOW 2.1 | conectiva linux Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4. | 0.8% | — |
| CVE-2026-78525 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78505 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69797 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69767 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69678 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69632 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-60723 | MED 6.3 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. | 0.8% | — |
| CVE-2025-27741 | HIGH 7.8 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2024-49111 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-36872 | MED 5.5 | microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-30300 | MED 6.5 | fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. | 0.8% | — |
| CVE-2022-22712 | MED 5.6 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.8% | — |
| CVE-2022-0972 | HIGH 8.8 | google chrome Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. | 0.8% | — |
| CVE-2021-31375 | HIGH 7.2 | juniper junos An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may ca | 0.8% | — |
| CVE-2020-3981 | MED 5.8 | vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI dev | 0.8% | — |
| CVE-2020-3940 | MED 5.9 | vmware workspace_one_boxer VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability. | 0.8% | — |
| CVE-2020-15937 | MED 4.7 | fortinet fortios An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard. | 0.8% | — |
| CVE-2020-12464 | MED 6.7 | linux linux_kernel usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. | 0.8% | — |
| CVE-2016-3193 | MED 5.4 | fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 and FortiAnalyzer 5.x before 5.0.13, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 allows remote authe | 0.8% | — |