IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-28306 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2023-28305 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2023-28278 MED 6.6 microsoft windows_server_2008 Windows DNS Server Remote Code Execution Vulnerability 0.9%
CVE-2022-35831 MED 5.5 microsoft windows_10 Windows Remote Access Connection Manager Information Disclosure Vulnerability 0.9%
CVE-2022-23767 HIGH 8.8 hanssak securegate This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privile 0.9%
CVE-2021-44172 MED 4.3 fortinet forticlient_endpoint_management_server An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClientEMS versions 7.0.0 through 7.0.4, 7.0.6 through 7.0.7, in all 6.4 and 6.2 version management interface may allow an unauthenticated attacker to gain information 0.9%
CVE-2021-20292 MED 6.7 debian debian_linux There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing op 0.9%
CVE-2021-0268 HIGH 8.8 juniper junos An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') weakness in J-web of Juniper Networks Junos OS leads to buffer overflows, segment faults, or other impacts, which allows an attacker to modify the integrity of the device 0.9%
CVE-2020-1402 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows ActiveX Installer Service improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows ActiveX Installer Service Eleva 0.9%
CVE-2020-0799 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when the Windows kernel fails to properly handle parsing of certain symbolic links, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 0.9%
CVE-2019-0931 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations, aka 'Windows Storage Service Elevation of Privilege Vulnerability'. 0.9%
CVE-2016-8961 MED 6.1 ibm bigfix_inventory IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to red 0.9%
CVE-2016-6418 MED 6.1 cisco videoscape_distribution_suite_service_manager Cross-site scripting (XSS) vulnerability in Cisco Videoscape Distribution Suite Service Manager (VDS-SM) 3.0 through 3.4.0 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCva14552. 0.9%
CVE-2026-71336 HIGH 8.8 microsoft windows_10_1607 Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-45584 HIGH 8.1 microsoft malware_protection_engine Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-49670 MED 6.5 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2023-36030 MED 6.1 microsoft dynamics_365 Microsoft Dynamics 365 Sales Spoofing Vulnerability 0.9%
CVE-2023-30867 MED 4.9 apache streampark In the Streampark platform, when users log in to the system and use certain features, some pages provide a name-based fuzzy search, such as job names, role names, etc. The sql syntax :select * from table where jobName like '%jobName%'. However, the jobName fie 0.9%
CVE-2021-34462 HIGH 7.0 microsoft windows_10 Windows AppX Deployment Extensions Elevation of Privilege Vulnerability 0.9%
CVE-2021-26428 MED 4.4 microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability 0.9%
CVE-2021-22113 MED 5.3 vmware spring_cloud_netflix_zuul Applications using the “Sensitive Headers” functionality in Spring Cloud Netflix Zuul 2.2.6.RELEASE and below may be vulnerable to bypassing the “Sensitive Headers” restriction when executing requests with specially constructed URLs. Applications that use Spri 0.9%
CVE-2021-20486 MED 6.5 ibm cloud_pak_for_data IBM Cloud Pak for Data 3.0 could allow an authenticated user to obtain sensitive information when installed with additional plugins. IBM X-Force ID: 197668. 0.9%
CVE-2021-1695 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 0.9%
CVE-2019-18654 MED 6.1 avg anti-virus A Cross Site Scripting (XSS) issue exists in AVG AntiVirus (Internet Security Edition) 19.3.3084 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. 0.9%
CVE-2019-18653 MED 6.1 avast antivirus A Cross Site Scripting (XSS) issue exists in Avast AntiVirus (Free, Internet Security, and Premiere Edition) 19.3.2369 build 19.3.4241.440 in the Network Notification Popup, allowing an attacker to execute JavaScript code via an SSID Name. 0.9%