57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0217 | MED 6.7 | cisco asr_5000_firmware A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system. The vulnerability is due to insuffi | 0.9% | — |
| CVE-2017-0449 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged proc | 0.9% | — |
| CVE-2017-0447 | HIGH 7.0 | google android An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 0.9% | — |
| CVE-2017-0446 | HIGH 7.0 | google android An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 0.9% | — |
| CVE-2017-0442 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 0.9% | — |
| CVE-2017-0440 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 0.9% | — |
| CVE-2016-5235 | MED 6.1 | f5 websafe_alert_server A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert. | 0.9% | — |
| CVE-2025-27742 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 0.9% | — |
| CVE-2024-30323 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0.9% | — |
| CVE-2020-7860 | HIGH 7.8 | unegg_project unegg UnEGG v0.5 and eariler versions have a Integer overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by UnEGG. Attackers could exploit this and arbitrary code execution. This issue affects: Estsoft UnEGG 0.5 version | 0.9% | — |
| CVE-2020-12820 | MED 5.4 | fortinet fortios Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attacker authenticated to the SSL VPN to crash the FortiClient NAC daemon (fcnacd) and potentially execute arbitrary | 0.9% | — |
| CVE-2019-1701 | MED 4.8 | cisco adaptive_security_appliance_software Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of | 0.9% | — |
| CVE-2018-15426 | MED 4.8 | cisco unity_connection A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is du | 0.9% | — |
| CVE-2018-0047 | HIGH 8.0 | juniper junos_space A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user | 0.9% | — |
| CVE-2017-15703 | MED 5.0 | apache nifi Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on | 0.9% | — |
| CVE-2017-0336 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user per | 0.9% | — |
| CVE-2017-0334 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user per | 0.9% | — |
| CVE-2026-62837 | MED 6.5 | microsoft sharepoint_server Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-41109 | HIGH 8.8 | microsoft visual_studio_code Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network. | 0.9% | — |
| CVE-2024-49032 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38582 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential hang in nilfs_detach_log_writer() Syzbot has reported a potential hang in nilfs_detach_log_writer() called during nilfs2 unmount. Analysis revealed that this is becaus | 0.9% | — |
| CVE-2024-35270 | MED 5.3 | microsoft windows_10_1507 Windows iSCSI Service Denial of Service Vulnerability | 0.9% | — |
| CVE-2023-20046 | HIGH 8.8 | cisco staros A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied credentials | 0.9% | — |
| CVE-2023-20020 | HIGH 8.6 | cisco broadworks_application_delivery_platform_device_management A vulnerability in the Device Management Servlet application of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended Services Platform could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an aff | 0.9% | — |
| CVE-2021-23013 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, the Traffic Management Microkernel (TMM) may stop responding when processing Stream Control Transmission Protocol (SCTP) | 0.9% | — |