IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2026-73009 CRIT 9.8 microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2026-32173 HIGH 8.6 microsoft azure_sre_agent Improper authentication in Azure SRE Agent allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-20191 HIGH 7.5 cisco catalyst_center A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this v 0.9%
CVE-2025-58717 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2025-55700 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2025-49752 CRIT 10.0 microsoft azure_bastion_developer Azure Bastion Elevation of Privilege Vulnerability 0.9%
CVE-2024-47571 HIGH 8.1 fortinet fortimanager An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials. 0.9%
CVE-2024-3385 HIGH 7.5 paloaltonetworks pan-os A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to reboot hardware-based firewalls. Repeated attacks eventually cause the firewall to enter maintenance mode, which requires manual intervention to bring the firewall 0.9%
CVE-2023-20896 MED 5.9 vmware vcenter_server The VMware vCenter Server contains an out-of-bounds read vulnerability in the implementation of the DCERPC protocol. A malicious actor with network access to vCenter Server may trigger an out-of-bounds read by sending a specially crafted packet leading to deni 0.9%
CVE-2021-24024 MED 4.3 fortinet fortiadc A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log files. 0.9%
CVE-2021-1625 MED 5.8 cisco ios_xe A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists because ICMP and UDP resp 0.9%
CVE-2020-16892 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.</p> <p>To exploit the vulnerability, a 0.9%
CVE-2019-14816 HIGH 7.8 canonical ubuntu_linux There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. 0.9%
CVE-2018-13367 MED 5.3 fortinet fortios An information exposure vulnerability in FortiOS 6.2.3, 6.2.0 and below may allow an unauthenticated attacker to gain platform information such as version, models, via parsing a JavaScript file through admin webUI. 0.9%
CVE-2018-13365 MED 5.3 fortinet fortios An Information Exposure vulnerability in Fortinet FortiOS 6.0.1, 5.6.5 and below, allow attackers to learn private IP as well as the hostname of FortiGate via Application Control Block page. 0.9%
CVE-2017-6650 HIGH 7.8 cisco nx-os A vulnerability in the Telnet CLI command of Cisco NX-OS System Software 7.1 through 7.3 running on Cisco Nexus Series Switches could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input v 0.9%
CVE-2017-5328 HIGH 7.5 paloaltonetworks terminal_services_agent Palo Alto Networks Terminal Services Agent before 7.0.7 allows attackers to spoof arbitrary users via unspecified vectors. 0.9%
CVE-2016-1448 HIGH 8.8 cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.7 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuy92706. 0.9%
CVE-2026-40379 CRIT 9.3 microsoft entra_id Exposure of sensitive information to an unauthorized actor in Azure Entra ID allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2023-30995 HIGH 7.5 ibm aspera_faspex IBM Aspera Faspex 4.0 through 4.4.2 and 5.0 through 5.0.5 could allow a malicious actor to bypass IP whitelist restrictions using a specially crafted HTTP request. IBM X-Force ID: 254268. 0.9%
CVE-2022-35822 HIGH 7.1 microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability 0.9%
CVE-2022-20814 HIGH 7.4 cisco telepresence_video_communication_server A vulnerability in the certificate validation of Cisco&nbsp;Expressway-C and Cisco&nbsp;TelePresence VCS could allow an unauthenticated, remote attacker to gain unauthorized access to sensitive data.&nbsp;&nbsp;The vulnerability is due to a lack of validation 0.9%
CVE-2021-36967 HIGH 8.0 microsoft windows_10 Windows WLAN AutoConfig Service Elevation of Privilege Vulnerability 0.9%
CVE-2019-1719 MED 6.1 cisco identity_services_engine A vulnerability in the web-based guest portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to 0.9%
CVE-2018-0367 MED 5.4 cisco registered_envelope_service A vulnerability in the web-based management interface of the Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of the affected ser 0.9%