57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-21781 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-43640 | MED 5.5 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 12.0.1.12430. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.9% | — |
| CVE-2021-36928 | MED 6.0 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-3117 | MED 4.7 | cisco content_security_management_appliance A vulnerability in the API Framework of Cisco AsyncOS for Cisco Web Security Appliance (WSA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to inject crafted HTTP headers in the web server's response. The | 0.9% | — |
| CVE-2019-8921 | MED 6.5 | bluez bluez An issue was discovered in bluetoothd in BlueZ through 5.48. The vulnerability lies in the handling of a SVC_ATTR_REQ by the SDP implementation. By crafting a malicious CSTATE, it is possible to trick the server into returning more bytes than the buffer actual | 0.9% | — |
| CVE-2012-2848 | MED 4.3 | google chrome The drag-and-drop implementation in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows user-assisted remote attackers to bypass intended file access restrictions via a crafted web site. | 0.9% | — |
| CVE-2026-65815 | HIGH 8.8 | microsoft dynamics_365 Deserialization of untrusted data in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. | 0.9% | — |
| CVE-2026-50682 | HIGH 7.1 | microsoft windows_10_21h2 Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network. | 0.9% | — |
| CVE-2026-41605 | HIGH 7.3 | apache thrift Integer Overflow or Wraparound vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 0.9% | — |
| CVE-2025-21321 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21320 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21319 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21318 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21316 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21180 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows exFAT File System allows an unauthorized attacker to execute code locally. | 0.9% | — |
| CVE-2024-3382 | HIGH 7.5 | paloaltonetworks pan-os A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 Series devices that ar | 0.9% | — |
| CVE-2023-32047 | HIGH 7.8 | microsoft paint_3d Paint 3D Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-23011 | HIGH 7.5 | f5 big-ip_access_policy_manager On certain hardware BIG-IP platforms, in version 15.1.x before 15.1.4 and 14.1.x before 14.1.3, virtual servers may stop responding while processing TCP traffic due to an issue in the SYN Cookie Protection feature. Note: Software versions which have reached En | 0.9% | — |
| CVE-2022-22180 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the processing of specific IPv6 packets on certain EX Series devices may lead to exhaustion of DMA memory causing a Denial of Service (DoS). Over time, exploitation of this vulnerability | 0.9% | — |
| CVE-2022-22174 | HIGH 7.5 | juniper junos A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the con | 0.9% | — |
| CVE-2022-22171 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN whic | 0.9% | — |
| CVE-2022-22170 | HIGH 7.5 | juniper junos A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which | 0.9% | — |
| CVE-2022-22153 | HIGH 7.5 | juniper junos An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 allows an unauthenticated networ | 0.9% | — |
| CVE-2022-20914 | MED 4.9 | cisco identity_services_engine A vulnerability in the External RESTful Services (ERS) API of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker to obtain sensitive information. This vulnerability is due to excessive verbosity in a specific REST API o | 0.9% | — |
| CVE-2022-20744 | MED 6.5 | cisco secure_firewall_management_center A vulnerability in the input protection mechanisms of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view data without proper authorization. This vulnerability exists because of a protection mechanism that rel | 0.9% | — |