57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-34161 | MED 5.3 | f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak prev | 0.9% | — |
| CVE-2023-20872 | HIGH 8.8 | vmware fusion VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation. | 0.9% | — |
| CVE-2022-49407 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dlm: fix plock invalid read This patch fixes an invalid read showed by KASAN. A unlock will allocate a "struct plock_op" and a followed send_op() will append it to a global send_list data st | 0.9% | — |
| CVE-2022-35735 | HIGH 7.2 | f5 big-ip_access_policy_manager In BIG-IP Versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and all versions of 13.1.x, an authenticated attacker with Resource Administrator or Manager privileges can create or modify existing monitor objects in the Configuratio | 0.9% | — |
| CVE-2020-7831 | HIGH 8.8 | inogard ebiz4u A vulnerability in the web-based contract management service interface Ebiz4u of INOGARD could allow an victim user to download any file. The attacker is able to use startup menu directory via directory traversal for automatic execution. The victim user need t | 0.9% | — |
| CVE-2026-70563 | HIGH 8.1 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2026-69739 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69734 | MED 6.5 | microsoft 365_apps Integer overflow or wraparound in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69719 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-69626 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-62782 | MED 6.5 | microsoft windows_10_1607 Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-40400 | HIGH 8.0 | microsoft windows_10_1607 Relative path traversal in Windows PowerShell allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-40374 | MED 6.5 | microsoft power_automate_for_desktop Exposure of sensitive information to an unauthorized actor in Power Automate allows an authorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2024-30012 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2021-29681 | MED 5.3 | ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow an attacker to obtain sensitive information by injecting parameters into an HTML query. This information could be used in further attacks against the system. IBM X-Force ID: 199918. | 0.9% | — |
| CVE-2021-20582 | MED 5.3 | ibm security_secret_server IBM Security Secret Server up to 11.0 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 199328. | 0.9% | — |
| CVE-2018-0190 | MED 6.1 | cisco ios_xe Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities | 0.9% | — |
| CVE-2018-0188 | MED 6.1 | cisco ios_xe Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities | 0.9% | — |
| CVE-2018-0186 | MED 6.1 | cisco ios_xe Multiple vulnerabilities in the web-based user interface (web UI) of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web UI of the affected software. The vulnerabilities | 0.9% | — |
| CVE-2018-0145 | MED 6.1 | cisco data_center_analytics_framework A vulnerability in the web-based management interface of the Cisco Data Center Analytics Framework application could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface of an affect | 0.9% | — |
| CVE-2018-0129 | MED 6.1 | cisco data_center_analytics_framework A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an a | 0.9% | — |
| CVE-2018-0128 | MED 6.1 | cisco data_center_analytics_framework A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affe | 0.9% | — |
| CVE-2018-0098 | MED 6.1 | cisco wap150_firmware A vulnerability in the web-based management interface of Cisco WAP150 Wireless-AC/N Dual Radio Access Point with Power over Ethernet (PoE) and WAP361 Wireless-AC/N Dual Radio Wall Plate Access Point with PoE could allow an unauthenticated, remote attacker to c | 0.9% | — |
| CVE-2017-6776 | MED 6.1 | cisco elastic_services_controller A vulnerability in the web framework of Cisco Elastic Services Controller (ESC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface. The vulnerability is due to insufficient validat | 0.9% | — |
| CVE-2017-12323 | MED 6.1 | cisco registered_envelope_service Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an undes | 0.9% | — |