57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-32174 | HIGH 7.7 | microsoft azure_ai_bot_service Improper authentication in Azure Bot Service allows an authorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-68161 | MED 4.8 | apache log4j The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-att | 0.8% | — |
| CVE-2024-43603 | MED 5.5 | microsoft visual_studio Visual Studio Collector Service Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-20536 | HIGH 8.8 | cisco nexus_dashboard_fabric_controller A vulnerability in a REST API endpoint and web-based management interface of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with read-only privileges to execute arbitrary SQL commands on an affected device. This | 0.8% | — |
| CVE-2019-15212 | MED 4.6 | canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver. | 0.8% | — |
| CVE-2017-15803 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address is used | 0.8% | — |
| CVE-2017-15802 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls | 0.8% | — |
| CVE-2017-15801 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls | 0.8% | — |
| CVE-2017-15786 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x00000000001a78db." | 0.8% | — |
| CVE-2017-15783 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285ce1." | 0.8% | — |
| CVE-2017-15780 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285dad." | 0.8% | — |
| CVE-2017-15778 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285de7." | 0.8% | — |
| CVE-2017-15776 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285ec | 0.8% | — |
| CVE-2017-15775 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000259aa4." | 0.8% | — |
| CVE-2017-15773 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285d79." | 0.8% | — |
| CVE-2017-15772 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285e9 | 0.8% | — |
| CVE-2015-0707 | LOW 3.5 | cisco firesight_system_software Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Center allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCus85425. | 0.8% | — |
| CVE-2013-5541 | LOW 3.5 | cisco identity_services_engine Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495. | 0.8% | — |
| CVE-2013-1244 | LOW 3.5 | cisco webex_social Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199. | 0.8% | — |
| CVE-2025-65041 | CRIT 10.0 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-29820 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2025-21358 | HIGH 7.8 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.8% | — |
| CVE-2023-20173 | MED 4.9 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To e | 0.8% | — |
| CVE-2022-20633 | MED 5.3 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in authentication responses | 0.8% | — |
| CVE-2020-5927 | MED 6.1 | f5 big-ip_application_security_manager In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, BIG-IP ASM Configuration utility Stored-Cross Site Scripting. | 0.8% | — |