57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-1344 | LOW 3.5 | cisco ios Cisco IOS 15.1 and 15.2, when a clientless SSL VPN is configured, allows remote authenticated users to cause a denial of service (device reload) by using a web browser to refresh the SSL VPN portal page, as demonstrated by the Android browser, aka Bug ID CSCtr | 0.9% | — |
| CVE-2026-50324 | MED 5.9 | microsoft windows_10_1607 Loop with unreachable exit condition ('infinite loop') in Active Directory Federation Services (AD FS) allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2025-30474 | MED 5.0 | apache commons_vfs Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mas | 0.9% | — |
| CVE-2024-43470 | HIGH 7.3 | microsoft azure_network_watcher_agent Azure Network Watcher VM Agent Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-30072 | HIGH 7.8 | microsoft windows_11_22h2 Microsoft Event Trace Log File Parsing Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-35629 | MED 6.8 | microsoft windows_10_1507 Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-26933 | MED 5.5 | microsoft windows_10 Windows NTFS Information Disclosure Vulnerability | 0.9% | — |
| CVE-2020-1138 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker | 0.9% | — |
| CVE-2020-1132 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles file and folder links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status. To exploit th | 0.9% | — |
| CVE-2020-1121 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Clipboard Service. An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An attacker could then in | 0.9% | — |
| CVE-2017-3874 | MED 5.4 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2). Kno | 0.9% | — |
| CVE-2011-4777 | MED 4.3 | parallels parallels_plesk_panel Cross-site scripting (XSS) vulnerability in the Site Editor (aka SiteBuilder) feature in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to inject arbitrary web script or HTML via the login parameter to preferences.html. | 0.9% | — |
| CVE-2009-4910 | MED 4.3 | cisco asa_5580 Cross-site scripting (XSS) vulnerability in the WebVPN portal on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCsq78 | 0.9% | — |
| CVE-2025-24055 | MED 4.3 | microsoft windows_10_1507 Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to disclose information with a physical attack. | 0.9% | — |
| CVE-2024-26193 | MED 6.4 | microsoft azure_migrate Azure Migrate Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-2984 | HIGH 8.8 | pimcore pimcore Path Traversal: '\..\filename' in GitHub repository pimcore/pimcore prior to 10.5.22. | 0.9% | — |
| CVE-2023-23459 | CRIT 9.1 | priority-software priority Priority Windows may allow Command Execution via SQL Injection using an unspecified method. | 0.9% | — |
| CVE-2022-20920 | HIGH 7.7 | cisco ios A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional sit | 0.9% | — |
| CVE-2019-1802 | MED 4.8 | cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected sy | 0.9% | — |
| CVE-2026-70328 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-70327 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-56202 | MED 4.3 | apache traffic_server Expected Behavior Violation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.2.8, from 10.0.0 through 10.0.3. Users are recommended to upgrade to versions 9.2.9 or 10.0.4 or newer, which fixes the issue. | 0.9% | — |
| CVE-2023-31036 | HIGH 7.5 | nvidia triton_inference_server NVIDIA Triton Inference Server for Linux and Windows contains a vulnerability where, when it is launched with the non-default command line option --model-control explicit, an attacker may use the model load API to cause a relative path traversal. A successful | 0.9% | — |
| CVE-2023-28308 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2023-28307 | MED 6.6 | microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability | 0.9% | — |