IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-1289 MED 5.5 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Delivery Optimization does not properly enforce file share permissions, aka 'Windows Update Delivery Optimization Elevation of Privilege Vulnerability'. 0.7%
CVE-2011-1625 MED 5.4 cisco ios Cisco IOS 12.2, 12.3, 12.4, 15.0, and 15.1, when the data-link switching (DLSw) feature is configured, allows remote attackers to cause a denial of service (device crash) by sending a sequence of malformed packets and leveraging a "narrow timing window," aka B 0.7%
CVE-2026-5485 HIGH 7.8 amazon athena_odbc OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a 0.7%
CVE-2026-40982 CRIT 9.1 vmware spring_cloud_config Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Sprin 0.7%
CVE-2025-59285 HIGH 7.0 microsoft azure_monitor_agent Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2024-47696 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix WARNING:at_kernel/workqueue.c:#check_flush_dependency In the commit aee2424246f9 ("RDMA/iwcm: Fix a use-after-free related to destroying CM IDs"), the function flush_workqueue 0.7%
CVE-2024-36510 MED 5.3 fortinet forticlientems An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthen 0.7%
CVE-2024-20665 MED 6.1 microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability 0.7%
CVE-2022-27674 HIGH 7.5 amd amd_uprof Insufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service. 0.7%
CVE-2022-20690 MED 5.3 cisco ata_190_firmware Multiple vulnerabilities in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, adjacent attacker to cause Cisco Discovery Protocol memory corruption on an affected device. Thes 0.7%
CVE-2021-20420 MED 4.3 ibm security_guardium IBM Security Guardium 11.2 could disclose sensitive information due to reliance on untrusted inputs that could aid in further attacks against the system. IBM X-Force ID: 196281. 0.7%
CVE-2020-5425 HIGH 7.9 vmware single_sign-on_for_tanzu Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1 are vulnerable to user impersonation attack.If two users are logged in to the SSO operator dashboard at the same time, with the same userna 0.7%
CVE-2020-3264 HIGH 7.1 cisco sd-wan_firmware A vulnerability in Cisco SD-WAN Solution software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending 0.7%
CVE-2020-0896 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles hard links, aka 'Windows Hard Link Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0840, CVE-2020-0841, CVE-2020-0849. 0.7%
CVE-2019-15998 MED 5.3 cisco ios_xr A vulnerability in the access-control logic of the NETCONF over Secure Shell (SSH) of Cisco IOS XR Software may allow connections despite an access control list (ACL) that is configured to deny access to the NETCONF over SSH of an affected device. The vulnerab 0.7%
CVE-1999-0381 HIGH 7.2 debian debian_linux super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root access. 0.7%
CVE-2026-69268 HIGH 8.8 microsoft sharepoint_server Improper access control in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 0.7%
CVE-2026-25077 HIGH 8.8 apache cloudstack Account users are allowed by default to register templates to be downloaded directly to the primary storage for deploying instances using the KVM hypervisor. Due to missing file name sanitization, an attacker can register malicious templates to execute arbitra 0.7%
CVE-2024-22281 HIGH 7.5 apache helix ** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies. This issue affects Apache Helix Front (UI): all versions. As this project is ret 0.7%
CVE-2024-20307 MED 6.8 cisco ios A vulnerability in the IKEv1 fragmentation code of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a heap overflow, resulting in an affected device reloading. This vulnerability exists because crafted, f 0.7%
CVE-2022-44694 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7%
CVE-2021-26430 MED 6.0 microsoft azure_sphere Azure Sphere Denial of Service Vulnerability 0.7%
CVE-2021-20407 MED 5.3 ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185. 0.7%
CVE-2021-0217 HIGH 7.4 juniper junos A vulnerability in processing of certain DHCP packets from adjacent clients on EX Series and QFX Series switches running Juniper Networks Junos OS with DHCP local/relay server configured may lead to exhaustion of DMA memory causing a Denial of Service (DoS). O 0.7%
CVE-2020-3429 MED 6.5 cisco ios_xe A vulnerability in the WPA2 and WPA3 security implementation of Cisco IOS XE Wireless Controller Software for the Cisco Catalyst 9000 Family could allow an unauthenticated, adjacent attacker to cause denial of service (DoS) condition on an affected device. The 0.7%