IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2018-0003 MED 6.5 juniper junos A specially crafted MPLS packet received or processed by the system, on an interface configured with MPLS, will store information in the system memory. Subsequently, if this stored information is accessed, this may result in a kernel crash leading to a denial 0.9%
CVE-2017-4940 MED 6.1 vmware esxi The ESXi Host Client in VMware ESXi (6.5 before ESXi650-201712103-SG, 5.5 before ESXi600-201711103-SG and 5.5 before ESXi550-201709102-SG) contains a vulnerability that may allow for stored cross-site scripting (XSS). An attacker can exploit this vulnerability 0.9%
CVE-2010-4243 MED 4.9 linux linux_kernel fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec 0.9%
CVE-2010-3858 MED 4.9 canonical ubuntu_linux The setup_arg_pages function in fs/exec.c in the Linux kernel before 2.6.36, when CONFIG_STACK_GROWSDOWN is used, does not properly restrict the stack memory consumption of the (1) arguments and (2) environment for a 32-bit application on a 64-bit platform, wh 0.9%
CVE-2026-55051 MED 6.5 microsoft sharepoint_server Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to disclose information over a network. 0.9%
CVE-2026-24888 MED 6.5 microsoft maker.js Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to 0.9%
CVE-2025-30067 HIGH 7.2 apache kylin Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Kylin. If an attacker gets access to Kylin's system or project admin permission, the JDBC connection configuration maybe altered to execute arbitrary code from the remote. You a 0.9%
CVE-2023-28506 HIGH 8.8 rocketsoftware unidata Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5 build 1001 or 12.2.1 build 2002 suffer from a stack-based buffer overflow, where a string is copied into a buffer using a memcpy-like function and a user-provided 0.9%
CVE-2023-20883 HIGH 7.5 vmware spring_boot In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache. 0.9%
CVE-2022-22300 MED 4.3 fortinet fortianalyzer A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 through 6.0.11, FortiAnalyzer version 6.2.0 through 6.2.9, FortiAnalyzer version 6.4.0 through 6.4.7, FortiAnalyze 0.9%
CVE-2021-41376 LOW 2.3 microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability 0.9%
CVE-2020-3474 MED 4.3 cisco ios_xe Multiple vulnerabilities in the web management framework of Cisco IOS XE Software could allow an authenticated, remote attacker with read-only privileges to gain unauthorized read access to sensitive data or cause the web management software to hang or crash, 0.9%
CVE-2020-0989 MED 5.5 microsoft windows_10 <p>An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions. An attacker who successfully exploited this vulnerability could bypass access restrictions to read files.</p> <p>To exploit 0.9%
CVE-2020-0858 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the &quot;Public Account Pictures&quot; folder improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Elevation of Privil 0.9%
CVE-2017-6675 MED 6.1 cisco industrial_network_director A vulnerability in the web interface of Cisco Industrial Network Director could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against an affected system. More Information: CSCvd25405. Known Affected Releases 0.9%
CVE-2013-0885 HIGH 7.5 google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors. 0.9%
CVE-2026-23669 HIGH 8.8 microsoft windows_10_1607 Use after free in RPC Runtime allows an authorized attacker to execute code over a network. 0.9%
CVE-2025-29806 MED 6.5 microsoft edge_chromium No cwe for this issue in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2022-20747 MED 6.5 cisco catalyst_sd-wan_manager A vulnerability in the History API of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected system. This vulnerability is due to insufficient API authorization checking on the underly 0.9%
CVE-2020-7483 HIGH 7.5 schneider-electric tristation_1131 **VERSION NOT SUPPORTED WHEN ASSIGNED** A vulnerability could cause certain data to be visible on the network when the 'password' feature is enabled. This vulnerability was discovered in and remediated in versions v4.9.1 and v4.10.1 on May 30, 2013. The 'passw 0.9%
CVE-2020-17033 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%
CVE-2020-17032 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%
CVE-2020-17028 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%
CVE-2020-17025 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%
CVE-2020-1546 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Engine improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted applicat 0.9%