57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-40677 | HIGH 7.2 | fortinet fortinac A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 allow | 0.8% | — |
| CVE-2022-21865 | HIGH 7.0 | microsoft windows_10 Connected Devices Platform Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-21864 | HIGH 7.0 | microsoft windows_10 Windows UI Immersive Server API Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-21860 | HIGH 7.0 | microsoft windows_10 Windows AppContracts API Server Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1709 | HIGH 7.0 | microsoft windows_10 Windows Win32k Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2020-3301 | MED 4.4 | cisco secure_firewall_management_center Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower User Agent Software could allow an attacker to access a sensitive part of an affected system with a high-privileged account. For more information about these vulne | 0.8% | — |
| CVE-2019-1007 | HIGH 7.8 | microsoft windows_10 An elevation of privilege exists in Windows Audio Service. An attacker who successfully exploited the vulnerability could run arbitrary code with elevated privileges. To exploit the vulnerability, an attacker could run a specially crafted application that coul | 0.8% | — |
| CVE-2017-14946 | HIGH 7.8 | artifex gsview Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address controls Branch Selection starting at mupdfnet64!mIncrementalSaveFile+0x0 | 0.8% | — |
| CVE-2017-14945 | HIGH 7.8 | artifex gsview Artifex GSView 6.0 Beta on Windows allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Possible Stack Corruption starting at KERNELBASE!RaiseException+0x0000000000000068." | 0.8% | — |
| CVE-2015-6311 | MED 6.1 | cisco wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0), 7.3(101.0), and 7.4(1.19) allow remote attackers to cause a denial of service (device outage) by sending malformed 802.11i management data to a managed access point, aka Bug ID CSCub65236. | 0.8% | — |
| CVE-2015-6294 | MED 6.1 | cisco ios Cisco IOS 15.2(3)E and earlier and IOS XE 3.6(2)E and earlier allow remote attackers to cause a denial of service (functionality loss) via crafted Cisco Discovery Protocol (CDP) packets, aka Bug ID CSCuu25770. | 0.8% | — |
| CVE-2015-4243 | MED 6.1 | cisco ios_xe The PPPoE establishment implementation in Cisco IOS XE 3.5.0S on ASR 1000 devices allows remote attackers to cause a denial of service (device reload) by sending malformed PPPoE Active Discovery Request (PADR) packets on the local network, aka Bug ID CSCty9420 | 0.8% | — |
| CVE-2005-3808 | MED 4.9 | linux linux_kernel Integer overflow in the invalidate_inode_pages2_range function in mm/truncate.c in Linux kernel 2.6.11 to 2.6.14 allows local users to cause a denial of service (hang) via 64-bit mmap calls that are not properly handled on a 32-bit system. | 0.8% | — |
| CVE-2004-0228 | HIGH 7.2 | linux linux_kernel Integer signedness error in the cpufreq proc handler (cpufreq_procctl) in Linux kernel 2.6 allows local users to gain privileges. | 0.8% | — |
| CVE-2026-30898 | HIGH 8.8 | apache airflow An example of BashOperator in Airflow documentation suggested a way of passing dag_run.conf in the way that could cause unsanitized user input to be used to escalate privileges of UI user to allow execute code on worker. Users should review if any of their own | 0.8% | — |
| CVE-2025-59249 | HIGH 8.8 | microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2023-5257 | LOW 3.5 | whitehsbg jndiexploit A vulnerability was found in WhiteHSBG JNDIExploit 1.4 on Windows. It has been rated as problematic. Affected by this issue is the function handleFileRequest of the file src/main/java/com/feihong/ldap/HTTPServer.java. The manipulation leads to path traversal. | 0.8% | — |
| CVE-2023-48784 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6.4 all versions command line interface may allow a local privileged attacker with super-admin profile and CLI a | 0.8% | — |
| CVE-2023-29353 | MED 5.5 | microsoft sysinternals Sysinternals Process Monitor for Windows Denial of Service Vulnerability | 0.8% | — |
| CVE-2021-27195 | MED 5.9 | netop vision_pro Improper Authorization vulnerability in Netop Vision Pro up to and including to 9.7.1 allows an attacker to replay network traffic. | 0.8% | — |
| CVE-2021-22047 | MED 5.3 | vmware spring_data_rest In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that c | 0.8% | — |
| CVE-2020-1273 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, | 0.8% | — |
| CVE-2020-1162 | HIGH 7.8 | microsoft windows_10 An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vul | 0.8% | — |
| CVE-2016-8475 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the HTC input driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: An | 0.8% | — |
| CVE-2016-8474 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pr | 0.8% | — |