57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-43561 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43559 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43558 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43557 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43555 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-26238 | HIGH 7.8 | microsoft windows_10_21h2 Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-45861 | MED 6.5 | fortinet fortios An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2 | 0.8% | — |
| CVE-2021-36943 | MED 4.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-7877 | HIGH 8.0 | mastersoft zook_agent A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitra | 0.8% | — |
| CVE-2019-19697 | MED 6.7 | trendmicro antivirus_\+_security_2019 An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. | 0.8% | — |
| CVE-2018-10650 | HIGH 7.8 | citrix xenmobile_server There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | 0.8% | — |
| CVE-2017-6748 | MED 6.7 | cisco web_security_appliance A vulnerability in the CLI parser of the Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. The attacker must authenticate with valid operator-level or administrator-leve | 0.8% | — |
| CVE-2016-8480 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first require | 0.8% | — |
| CVE-2015-0716 | MED 6.8 | cisco unity_connection Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659. | 0.8% | — |
| CVE-2014-2190 | MED 6.8 | cisco broadband_access_center_telco_wireless_software Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Broadcast Access Center for Telco and Wireless (aka BAC-TW) allows remote attackers to hijack the authentication of arbitrary users for requests that make BAC-TW changes, aka Bug IDs | 0.8% | — |
| CVE-2014-0745 | MED 6.8 | cisco unified_contact_center_express_editor_software Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability subsystem in Cisco Unified Contact Center Express (Unified CCX) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCum95502. | 0.8% | — |
| CVE-2013-5494 | MED 6.8 | cisco unified_meetingplace Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified MeetingPlace Solution, as used in Unified MeetingPlace Web Conferencing and Unified MeetingPlace, allows remote attackers to hijack the authentication of arbitrary users, aka | 0.8% | — |
| CVE-2026-78524 | HIGH 8.8 | microsoft 365_apps Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78512 | HIGH 8.8 | microsoft 365_apps Numeric truncation error in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78511 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-72973 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-72972 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69764 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69759 | HIGH 8.8 | microsoft 365_apps Stack-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-69742 | HIGH 8.8 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Publisher allows an unauthorized attacker to execute code over a network. | 0.8% | — |