57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-73009 | CRIT 9.8 | microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-32173 | HIGH 8.6 | microsoft azure_sre_agent Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-20191 | HIGH 7.5 | cisco catalyst_center A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this v | 0.9% | — |
| CVE-2025-58717 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-55700 | MED 6.5 | microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-49752 | CRIT 10.0 | microsoft azure_bastion_developer Azure Bastion Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2024-47571 | HIGH 8.1 | fortinet fortimanager An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials. | 0.9% | — |
| CVE-2024-3385 | HIGH 7.5 | paloaltonetworks pan-os A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall | 0.9% | — |
| CVE-2023-20896 | MED 5.9 | vmware vcenter_server The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to deni | 0.9% | — |
| CVE-2021-24024 | MED 4.3 | fortinet fortiadc A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log files. | 0.9% | — |
| CVE-2021-1625 | MED 5.8 | cisco ios_xe A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP resp | 0.9% | — |
| CVE-2020-16892 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a | 0.9% | — |
| CVE-2019-14816 | HIGH 7.8 | canonical ubuntu_linux There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | 0.9% | — |
| CVE-2018-13367 | MED 5.3 | fortinet fortios An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as version, models, via parsing a JavaScript file through admin webUI. | 0.9% | — |
| CVE-2018-13365 | MED 5.3 | fortinet fortios An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page. | 0.9% | — |
| CVE-2017-6650 | HIGH 7.8 | cisco nx-os A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input v | 0.9% | — |
| CVE-2017-5328 | HIGH 7.5 | paloaltonetworks terminal_services_agent Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors. | 0.9% | — |
| CVE-2016-1448 | HIGH 8.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706. | 0.9% | — |
| CVE-2026-40379 | CRIT 9.3 | microsoft entra_id Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2023-30995 | HIGH 7.5 | ibm aspera_faspex IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268. | 0.9% | — |
| CVE-2022-35822 | HIGH 7.1 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2022-20814 | HIGH 7.4 | cisco telepresence_video_communication_server A vulnerability in the certificate validation of Cisco Expressway-C and Cisco TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data. The vulnerability is due to a lack of validation | 0.9% | — |
| CVE-2021-36967 | HIGH 8.0 | microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2019-1719 | MED 6.1 | cisco identity_services_engine A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to | 0.9% | — |
| CVE-2018-0367 | MED 5.4 | cisco registered_envelope_service A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected ser | 0.9% | — |