IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2019-12705 MED 6.1 cisco telepresence_video_communication_server A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-ba 0.8%
CVE-2018-0465 MED 6.1 cisco sf300-08_firmware A vulnerability in the web-based management interface of Cisco Small Business 300 Series Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected system. The 0.8%
CVE-2016-6401 MED 5.3 cisco carrier_routing_system Cisco Carrier Routing System (CRS) 5.1 and 5.1.4, as used in CRS Carrier Grade Services for CRS-1 and CRS-3 devices, allows remote attackers to cause a denial of service (line-card reload) via crafted IPv6-over-MPLS packets, aka Bug ID CSCva32494. 0.8%
CVE-2012-2421 LOW 1.8 intuit quickbooks Absolute path traversal vulnerability in the intu-help-qb (aka Intuit Help System Async Pluggable Protocol) handlers in HelpAsyncPluggableProtocol.dll in Intuit QuickBooks 2009 through 2012, when Internet Explorer is used, might allow remote attackers to read 0.8%
CVE-2010-3850 LOW 2.1 canonical ubuntu_linux The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call. 0.8%
CVE-2004-0497 LOW 2.1 conectiva linux Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4. 0.8%
CVE-2026-78525 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-78505 HIGH 8.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69797 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69767 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69678 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2026-69632 HIGH 8.8 microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-60723 MED 6.3 microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an authorized attacker to deny service over a network. 0.8%
CVE-2025-27741 HIGH 7.8 microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to elevate privileges locally. 0.8%
CVE-2024-49111 MED 6.6 microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability 0.8%
CVE-2023-36872 MED 5.5 microsoft vp9_video_extensions VP9 Video Extensions Information Disclosure Vulnerability 0.8%
CVE-2022-30300 MED 6.5 fortinet fortiweb A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. 0.8%
CVE-2022-22712 MED 5.6 microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability 0.8%
CVE-2022-0972 HIGH 8.8 google chrome Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. 0.8%
CVE-2021-31375 HIGH 7.2 juniper junos An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BGP update which may ca 0.8%
CVE-2020-3981 MED 5.8 vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds read vulnerability due to a time-of-check time-of-use issue in ACPI dev 0.8%
CVE-2020-3940 MED 5.9 vmware workspace_one_boxer VMware Workspace ONE SDK and dependent mobile application updates address sensitive information disclosure vulnerability. 0.8%
CVE-2020-15937 MED 4.7 fortinet fortios An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform a stored cross site scripting attack (XSS) via the IPS and WAF logs dashboard. 0.8%
CVE-2020-12464 MED 6.7 linux linux_kernel usb_sg_cancel in drivers/usb/core/message.c in the Linux kernel before 5.6.8 has a use-after-free because a transfer occurs without a reference, aka CID-056ad39ee925. 0.8%
CVE-2016-3193 MED 5.4 fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in the appliance web-application in Fortinet FortiManager 5.x before 5.0.12, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 and FortiAnalyzer 5.x before 5.0.13, 5.2.x before 5.2.6, and 5.4.x before 5.4.1 allows remote authe 0.8%