57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-44998 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: atm: idt77252: prevent use after free in dequeue_rx() We can't dereference "skb" after calling vcc->push() because the skb is released. | 0.8% | — |
| CVE-2024-38175 | CRIT 9.6 | microsoft azure_managed_instance_for_apache_cassandra An improper access control vulnerability in the Azure Managed Instance for Apache Cassandra allows an authenticated attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-36042 | MED 6.2 | microsoft visual_studio_2019 Visual Studio Denial of Service Vulnerability | 0.8% | — |
| CVE-2022-41105 | MED 5.5 | microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-41104 | MED 5.5 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2022-41060 | MED 5.5 | microsoft 365_apps Microsoft Word Information Disclosure Vulnerability | 0.8% | — |
| CVE-2021-33744 | MED 5.3 | microsoft windows_10 Windows Secure Kernel Mode Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2021-29964 | HIGH 7.1 | mozilla firefox A locally-installed hostile program could send `WM_COPYDATA` messages that Firefox would process incorrectly, leading to an out-of-bounds read. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Thun | 0.8% | — |
| CVE-2021-29686 | HIGH 8.8 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015 | 0.8% | — |
| CVE-2021-1271 | MED 4.8 | cisco web_security_virtual_appliance A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface of an affected dev | 0.8% | — |
| CVE-2020-24559 | HIGH 7.8 | trendmicro apex_one A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow | 0.8% | — |
| CVE-2020-1602 | HIGH 7.1 | juniper junos When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may remotely take over the code ex | 0.8% | — |
| CVE-2020-0942 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 0.8% | — |
| CVE-2020-0936 | HIGH 7.1 | microsoft windows_10 An elevation of privilege vulnerability exists when a Windows scheduled task improperly handles file redirections, aka 'Windows Scheduled Task Elevation of Privilege Vulnerability'. | 0.8% | — |
| CVE-2017-7735 | MED 5.4 | fortinet fortios A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via the "Groups" input while creating or editing User Groups. | 0.8% | — |
| CVE-2017-7734 | MED 5.4 | fortinet fortios A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions. | 0.8% | — |
| CVE-2017-6707 | HIGH 8.2 | cisco staros A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series 11.0 through 21.0, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker | 0.8% | — |
| CVE-2016-8460 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user p | 0.8% | — |
| CVE-2015-6295 | MED 4.8 | cisco nx-os Cisco NX-OS 6.1(2)I3(4) and 7.0(3)I1(1) on Nexus 9000 (N9K) devices allows remote attackers to cause a denial of service (CPU consumption or control-plane instability) or trigger unintended traffic forwarding via a Layer 2 packet with a reserved VLAN number, a | 0.8% | — |
| CVE-2026-32191 | CRIT 9.8 | microsoft bing_images Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2024-26010 | HIGH 7.5 | fortinet fortios A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitchManager version 7.2.0 through 7.2.3, 7.0.1 through 7.0.3, FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7. | 0.8% | — |
| CVE-2023-0925 | CRIT 9.8 | softwareag webmethods Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which hosts a Java RMI registry (listening on TCP port 2099 by default) and two RMI interfaces (listening on a single, dynamically assigned TCP high port). Port 2099 ser | 0.8% | — |
| CVE-2021-1570 | MED 6.5 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabili | 0.8% | — |
| CVE-2020-0772 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Elevation of Privilege Vulner | 0.8% | — |
| CVE-2016-1434 | MED 6.5 | cisco ip_phone_8800_series_firmware The license-certificate upload functionality on Cisco 8800 phones with software 11.0(1) allows remote authenticated users to delete arbitrary files via an invalid file, aka Bug ID CSCuz03010. | 0.8% | — |