57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-37379 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2022-34705 | HIGH 7.8 | microsoft windows_10 Windows Defender Credential Guard Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-36938 | MED 5.5 | microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-34457 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-34454 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-34440 | MED 5.5 | microsoft windows_10 GDI+ Information Disclosure Vulnerability | 0.9% | — |
| CVE-2021-33763 | MED 5.5 | microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-26558 | MED 4.2 | bluetooth bluetooth_core_specification Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the | 0.9% | — |
| CVE-2019-6664 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.0.0 and 14.1.0-14.1.0.6, under certain conditions, network protections on the management port do not follow current best practices. | 0.9% | — |
| CVE-2018-21032 | MED 4.3 | hitachi automation_director A vulnerability in Hitachi Command Suite prior to 8.7.1-00 and Hitachi Automation Director prior to 8.5.0-00 allow authenticated remote users to expose technical information through error messages. Hitachi Command Suite includes Hitachi Device Manager and Hita | 0.9% | — |
| CVE-2017-0535 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Produ | 0.9% | — |
| CVE-2006-3547 | MED 5.5 | vmware player EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying tha | 0.9% | — |
| CVE-2026-77889 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-77888 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-45639 | HIGH 7.5 | microsoft remote_desktop_client Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-42908 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-42145 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/core: Implement a limit on UMAD receive List The existing behavior of ib_umad, which maintains received MAD packets in an unbounded list, poses a risk of uncontrolled growth. As user-spac | 0.9% | — |
| CVE-2023-5727 | MED 6.5 | mozilla firefox The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* | 0.9% | — |
| CVE-2023-23384 | HIGH 7.3 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2020-2033 | MED 5.3 | paloaltonetworks globalprotect When the pre-logon feature is enabled, a missing certification validation in Palo Alto Networks GlobalProtect app can disclose the pre-logon authentication cookie to a man-in-the-middle attacker on the same local area network segment with the ability to manipu | 0.9% | — |
| CVE-2020-1014 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Microsoft Windows Update Client when it does not properly handle privileges, aka 'Microsoft Windows Update Client Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2020-0805 | MED 5.3 | microsoft windows_10 <p>A security feature bypass vulnerability exists when a Windows Projected Filesystem improperly handles file redirections. An attacker who successfully exploited this vulnerability could delete a targeted file they would not have permissions to.</p> <p>To exp | 0.9% | — |
| CVE-2019-1568 | MED 6.1 | paloaltonetworks demisto Cross-site scripting (XSS) vulnerability in Palo Alto Networks Demisto 4.5 build 40249 may allow an unauthenticated attacker to run arbitrary JavaScript or HTML. | 0.9% | — |
| CVE-2019-0041 | HIGH 8.6 | juniper junos On EX4300-MP Series devices with any lo0 filters applied, transit network traffic may reach the control plane via loopback interface (lo0). The device may fail to forward such traffic. This issue affects Juniper Networks Junos OS 18.2 versions prior to 18.2R1- | 0.9% | — |
| CVE-2018-11805 | MED 6.7 | apache spamassassin In Apache SpamAssassin before 3.4.3, nefarious CF files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA 3.4.3, we recommend that users should on | 0.9% | — |