57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1289 | MED 5.5 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'. | 0.7% | — |
| CVE-2011-1625 | MED 5.4 | cisco ios Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka B | 0.7% | — |
| CVE-2026-5485 | HIGH 7.8 | amazon athena_odbc OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a | 0.7% | — |
| CVE-2026-40982 | CRIT 9.1 | vmware spring_cloud_config Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Sprin | 0.7% | — |
| CVE-2025-59285 | HIGH 7.0 | microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | 0.7% | — |
| CVE-2024-47696 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency In the commit aee2424246f9 ("RDMA/iwcm: Fix a use-after-free related to destroying CM IDs"), the function flush_workqueue | 0.7% | — |
| CVE-2024-36510 | MED 5.3 | fortinet forticlientems An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthen | 0.7% | — |
| CVE-2024-20665 | MED 6.1 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2022-27674 | HIGH 7.5 | amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. | 0.7% | — |
| CVE-2022-20690 | MED 5.3 | cisco ata_190_firmware Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. Thes | 0.7% | — |
| CVE-2021-20420 | MED 4.3 | ibm security_guardium IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281. | 0.7% | — |
| CVE-2020-5425 | HIGH 7.9 | vmware single_sign-on_for_tanzu Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same userna | 0.7% | — |
| CVE-2020-3264 | HIGH 7.1 | cisco sd-wan_firmware A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending | 0.7% | — |
| CVE-2020-0896 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0849. | 0.7% | — |
| CVE-2019-15998 | MED 5.3 | cisco ios_xr A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerab | 0.7% | — |
| CVE-1999-0381 | HIGH 7.2 | debian debian_linux super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. | 0.7% | — |
| CVE-2026-69268 | HIGH 8.8 | microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-25077 | HIGH 8.8 | apache cloudstack Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitra | 0.7% | — |
| CVE-2024-22281 | HIGH 7.5 | apache helix ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is ret | 0.7% | — |
| CVE-2024-20307 | MED 6.8 | cisco ios A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, f | 0.7% | — |
| CVE-2022-44694 | HIGH 7.8 | microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-26430 | MED 6.0 | microsoft azure_sphere Azure Sphere Denial of Service Vulnerability | 0.7% | — |
| CVE-2021-20407 | MED 5.3 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185. | 0.7% | — |
| CVE-2021-0217 | HIGH 7.4 | juniper junos A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS with DHCP local/relay server configured may lead to exhaustion of DMA memory causing a Denial of Service (DoS). O | 0.7% | — |
| CVE-2020-3429 | MED 6.5 | cisco ios_xe A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause denial of service (DoS) condition on an affected device. The | 0.7% | — |