IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2023-47703 MED 5.3 ibm security_guardium_key_lifecycle_manager IBM Security Guardium Key Lifecycle Manager 4.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Forc 0.8%
CVE-2023-28365 CRIT 9.1 ui unifi_network_application A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored. 0.8%
CVE-2020-27726 MED 6.1 f5 big-ip_access_policy_manager In versions 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, and 12.1.0-12.1.5.2, a reflected cross-site scripting (XSS) vulnerability exists in the resource information page for authenticated users when a full webtop is configured on the BIG- 0.8%
CVE-2020-27719 MED 6.1 f5 big-ip_access_policy_manager On BIG-IP 16.0.0-16.0.0.1, 15.1.0-15.1.0.5, and 14.1.0-14.1.3, a cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility. 0.8%
CVE-2020-26077 MED 4.3 cisco iot_field_network_director A vulnerability in the access control functionality of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to view lists of users from different domains that are configured on an affected system. The vulnerability is due to imp 0.8%
CVE-2015-0674 MED 6.1 cisco cloud_web_security Cross-site scripting (XSS) vulnerability in the Alert Service of Cisco Cloud Web Security base revision allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. 0.8%
CVE-2026-81377 MED 6.5 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to perform tampering over a network. 0.8%
CVE-2026-56191 CRIT 10.0 microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. 0.8%
CVE-2026-47655 MED 6.5 microsoft graph Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network. 0.8%
CVE-2026-20934 HIGH 7.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2026-20848 HIGH 7.5 microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. 0.8%
CVE-2025-24039 HIGH 7.3 microsoft visual_studio_code Visual Studio Code Elevation of Privilege Vulnerability 0.8%
CVE-2024-38119 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Remote Code Execution Vulnerability 0.8%
CVE-2024-38057 HIGH 7.8 microsoft windows_10_1507 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability 0.8%
CVE-2024-38034 HIGH 7.8 microsoft windows_10_1507 Windows Filtering Platform Elevation of Privilege Vulnerability 0.8%
CVE-2024-24749 HIGH 7.5 geoserver geoserver GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.23.5 and 2.24.3, if GeoServer is deployed in the Windows operating system using an Apache Tomcat web application server, it is possible to bypass existi 0.8%
CVE-2023-34395 HIGH 7.8 apache apache-airflow-providers-odbc Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Software Foundation Apache Airflow ODBC Provider. In OdbcHook, A privilege escalation vulnerability exists in a system due to controllable ODBC driver pa 0.8%
CVE-2023-33162 MED 5.5 microsoft 365_apps Microsoft Excel Information Disclosure Vulnerability 0.8%
CVE-2022-31772 MED 5.3 ibm mq IBM MQ 8.0, 9.0 LTS, 9.1 CD, 9.1 LTS, 9.2 CD, and 9.2 LTS could allow an authenticated and authorized user to cause a denial of service to the MQTT channels. IBM X-Force ID: 228335. 0.8%
CVE-2022-2778 CRIT 9.8 octopus octopus_server In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. 0.8%
CVE-2022-25990 MED 5.3 f5 f5os-a On 1.0.x versions prior to 1.0.1, systems running F5OS-A software may expose certain registry ports externally. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated 0.8%
CVE-2021-1727 HIGH 7.8 microsoft windows_10 Windows Installer Elevation of Privilege Vulnerability 0.8%
CVE-2020-0868 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0867. 0.8%
CVE-2020-0867 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Orchestrator Service improperly handles file operations, aka 'Windows Update Orchestrator Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0868. 0.8%
CVE-2020-0857 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. 0.8%