57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-19167 | HIGH 7.8 | tobesoft nexacro Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution. | 0.7% | — |
| CVE-2013-6682 | MED 6.4 | cisco adaptive_security_appliance_software The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid ent | 0.7% | — |
| CVE-2026-58319 | CRIT 9.1 | apache doris Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster inte | 0.7% | — |
| CVE-2026-35423 | MED 5.4 | microsoft windows_10_1607 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-32151 | MED 6.5 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-21361 | HIGH 7.8 | microsoft office Microsoft Outlook Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2025-21187 | HIGH 7.8 | microsoft power_automate_for_desktop Microsoft Power Automate Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2025-21179 | MED 4.8 | microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability | 0.7% | — |
| CVE-2024-43505 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2024-36031 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem fo | 0.7% | — |
| CVE-2021-47274 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tracing: Correct the length check which causes memory corruption We've suffered from severe kernel crashes due to memory corruption on our production environment, like, Call Trace: [1640542 | 0.7% | — |
| CVE-2021-20432 | MED 6.5 | ibm spectrum_protect_plus IBM Spectrum Protect Plus 10.1.0 through 10.1.7 uses Cross-Origin Resource Sharing (CORS) which could allow an attacker to carry out privileged actions and retrieve sensitive information as the domain name is not being limited to only trusted domains. IBM X-Fo | 0.7% | — |
| CVE-2020-5740 | HIGH 7.8 | plex media_server Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges. | 0.7% | — |
| CVE-2018-15372 | HIGH 8.1 | cisco ios_xe A vulnerability in the MACsec Key Agreement (MKA) using Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) functionality of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to bypass authentication and pass traffic thr | 0.7% | — |
| CVE-2016-9774 | HIGH 7.8 | apache tomcat The postinst script in the tomcat6 package before 6.0.45+dfsg-1~deb7u4 on Debian wheezy, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u8 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, | 0.7% | — |
| CVE-2015-2337 | MED 5.8 | vmware fusion TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, w | 0.7% | — |
| CVE-2015-2336 | MED 5.8 | vmware fusion TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, | 0.7% | — |
| CVE-2026-7755 | HIGH 8.8 | langflow langflow IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. | 0.7% | — |
| CVE-2026-73029 | MED 6.5 | microsoft sql_server_2019 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2026-53405 | CRIT 9.8 | apache syncope Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can import arbitrary BPMN process definitions via the REST API and then start the process. When a BPMN process containing a Groovy scriptTa | 0.7% | — |
| CVE-2025-24053 | HIGH 7.2 | microsoft dataverse Improper authentication in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2025-23195 | HIGH 7.5 | apache ambari An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerability occurs due to insecure parsing of XML input using the `DocumentBuilderFactory` class without disabling e | 0.7% | — |
| CVE-2024-52054 | LOW 2.7 | wowza streaming_engine Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system. | 0.7% | — |
| CVE-2024-48903 | HIGH 7.8 | trendmicro deep_security_agent An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target | 0.7% | — |
| CVE-2024-36052 | HIGH 7.5 | rarlab winrar RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI escape sequences, a different issue than CVE-2024-33899. | 0.7% | — |