57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49094 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-49081 | MED 6.6 | microsoft windows_10_1809 Wireless Wide Area Network Service (WwanSvc) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-40373 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) is vulnerable to denial of service with a specially crafted query containing common table expressions. IBM X-Force ID: 263574. | 0.8% | — |
| CVE-2023-40372 | MED 5.3 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to denial of service with a specially crafted SQL statement using External Tables. IBM X-Force ID: 263499. | 0.8% | — |
| CVE-2023-36422 | HIGH 7.8 | microsoft windows_defender Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-29062 | MED 6.3 | fortinet fortisoar Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underlying filesystem with nginx permissions via crafted HTTP requests. | 0.8% | — |
| CVE-2021-33751 | HIGH 7.0 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-31952 | HIGH 7.8 | microsoft windows_10 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1351 | MED 6.1 | cisco webex_meetings A vulnerability in the web-based interface of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected service. The vulnerability is due to ins | 0.8% | — |
| CVE-2020-0900 | MED 5.5 | microsoft visual_studio_2015 An elevation of privilege vulnerability exists when the Visual Studio Extension Installer Service improperly handles file operations, aka 'Visual Studio Extension Installer Service Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2020-0899 | MED 5.5 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists when Microsoft Visual Studio updater service improperly handles file permissions, aka 'Microsoft Visual Studio Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2019-0015 | MED 5.4 | juniper junos A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish dynamic VPN connections until the device is rebooted. A deleted dynamic VPN connection should be immediately disallowed from establishing new VPN connections. Due t | 0.8% | — |
| CVE-2026-49844 | MED 5.9 | apache log4j Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026- | 0.8% | — |
| CVE-2026-24306 | CRIT 9.8 | microsoft azure_front_door Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-20951 | HIGH 7.8 | microsoft sharepoint_server Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2024-8196 | CRIT 9.8 | mintplexlabs anythingllm_desktop In mintplex-labs/anything-llm v1.5.11 desktop version for Windows, the application opens server port 3001 on 0.0.0.0 with no authentication by default. This vulnerability allows an attacker to gain full backend access, enabling them to perform actions such as | 0.8% | — |
| CVE-2024-53947 | CRIT 9.8 | apache superset Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Superset. Specifically, certain engine-specific functions are not checked, which allows attackers to bypass Apache Superset's SQL authorization. This i | 0.8% | — |
| CVE-2024-28898 | MED 6.3 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2023-20255 | MED 5.3 | cisco meeting_server A vulnerability in an API of the Web Bridge feature of Cisco Meeting Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of HTTP requests. An attacker could e | 0.8% | — |
| CVE-2022-33648 | HIGH 7.8 | microsoft office_online_server Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-1679 | HIGH 7.8 | debian debian_linux A use-after-free flaw was found in the Linux kernel’s Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privile | 0.8% | — |
| CVE-2021-1575 | MED 6.1 | cisco virtualized_voice_browser A vulnerability in the web-based management interface of Cisco Virtualized Voice Browser could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-b | 0.8% | — |
| CVE-2021-1395 | MED 4.7 | cisco packaged_contact_center_enterprise A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web | 0.8% | — |
| CVE-2020-3415 | HIGH 8.8 | cisco nx-os A vulnerability in the Data Management Engine (DME) of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with administrative privileges or cause a denial of service (DoS) condition on an affected device. The vulne | 0.8% | — |
| CVE-2020-17100 | MED 5.5 | microsoft visual_studio_2017 Visual Studio Tampering Vulnerability | 0.8% | — |