57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-4593 | MED 4.3 | ibm qradar_security_information_and_event_manager IBM QRadar 7.3.0 to 7.3.3 Patch 2 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-ForceID: 167743. | 0.8% | — |
| CVE-2019-1180 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the wcmsvc.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 0.8% | — |
| CVE-2019-1179 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authentica | 0.8% | — |
| CVE-2019-1178 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the ssdpsrv.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticat | 0.8% | — |
| CVE-2018-6687 | MED 5.5 | mcafee getsusp Loop with Unreachable Exit Condition ('Infinite Loop') in McAfee GetSusp (GetSusp) 3.0.0.461 and earlier allows attackers to DoS a manual GetSusp scan via while scanning a specifically crafted file . GetSusp is a free standalone McAfee tool that runs on severa | 0.8% | — |
| CVE-2014-0077 | MED 5.5 | linux linux_kernel drivers/vhost/net.c in the Linux kernel before 3.13.10, when mergeable buffers are disabled, does not properly validate packet lengths, which allows guest OS users to cause a denial of service (memory corruption and host OS crash) or possibly gain privileges o | 0.8% | — |
| CVE-2010-2963 | MED 6.2 | canonical ubuntu_linux drivers/media/video/v4l2-compat-ioctl32.c in the Video4Linux (V4L) implementation in the Linux kernel before 2.6.36 on 64-bit platforms does not validate the destination of a memory copy operation, which allows local users to write to arbitrary kernel memory l | 0.8% | — |
| CVE-2009-0343 | HIGH 7.2 | niels_provos systrace Niels Provos Systrace 1.6f and earlier on the x86_64 Linux platform allows local users to bypass intended access restrictions by making a 32-bit syscall with a syscall number that corresponds to a policy-compliant 64-bit syscall, related to race conditions tha | 0.8% | — |
| CVE-2026-69465 | HIGH 8.8 | microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-62562 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2024-33899 | HIGH 7.1 | rarlab winrar RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences. | 0.8% | — |
| CVE-2024-30371 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0.8% | — |
| CVE-2024-30367 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0.8% | — |
| CVE-2024-30365 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that | 0.8% | — |
| CVE-2023-28304 | HIGH 7.8 | microsoft odbc Microsoft ODBC and OLE DB Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-28284 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-41119 | HIGH 7.8 | microsoft visual_studio_2017 Visual Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-43244 | MED 6.5 | microsoft windows_10 Windows Kernel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-1130 | MED 4.8 | cisco catalyst_center A vulnerability in the web-based management interface of Cisco DNA Center software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability exists beca | 0.8% | — |
| CVE-2020-0786 | HIGH 7.1 | microsoft windows_10 A denial of service vulnerability exists when the Windows Tile Object Service improperly handles hard links, aka 'Windows Tile Object Service Denial of Service Vulnerability'. | 0.8% | — |
| CVE-2019-13631 | MED 6.8 | linux linux_kernel In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel through 5.2.1, a malicious USB device can send an HID report that triggers an out-of-bounds write during generation of debugging messages. | 0.8% | — |
| CVE-2018-0221 | MED 6.7 | cisco identity_services_engine A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session. The attacker n | 0.8% | — |
| CVE-2014-9326 | MED 4.3 | f5 big-ip_access_policy_manager The automatic signature update functionality in the (1) Phone Home feature in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, GTM, and Link Controller 11.5.0 through 11.6.0, ASM 10.0.0 through 11.6.0, and PEM 11.3.0 through 11.6.0 and the (2) Call Home feature in ASM | 0.8% | — |
| CVE-2012-4084 | MED 6.8 | cisco unified_computing_system Cross-site request forgery (CSRF) vulnerability in the web-management interface in the fabric interconnect (FI) component in Cisco Unified Computing System (UCS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCtg20755. | 0.8% | — |
| CVE-2025-21215 | MED 4.6 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |