57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1000 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1003, CVE-2020-1027. | 0.9% | — |
| CVE-2020-0985 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996. | 0.9% | — |
| CVE-2019-5006 | MED 5.5 | foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing. | 0.9% | — |
| CVE-2017-2317 | HIGH 8.6 | juniper northstar_controller A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading t | 0.9% | — |
| CVE-2016-2854 | HIGH 7.8 | linux linux_kernel The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. | 0.9% | — |
| CVE-2015-6400 | MED 4.3 | cisco emergency_responder Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547. | 0.9% | — |
| CVE-2025-59248 | HIGH 7.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2024-28896 | HIGH 7.5 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-26184 | MED 6.8 | microsoft windows_10_21h2 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2023-36557 | HIGH 7.8 | microsoft windows_10_1507 PrintHTML API Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-20080 | HIGH 8.6 | cisco ios A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation | 1.0% | — |
| CVE-2020-3549 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due | 1.0% | — |
| CVE-2020-0707 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2020-0704 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Wireless Network Manager Elevati | 1.0% | — |
| CVE-2014-3302 | MED 5.8 | cisco webex_meetings_server user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. | 1.0% | — |
| CVE-2002-1106 | HIGH 7.5 | cisco vpn_client Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks. | 1.0% | — |
| CVE-2026-67390 | MED 6.5 | microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2026-67383 | MED 6.5 | microsoft sql_server_2025 Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-26630 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2025-24057 | HIGH 7.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.0% | — |
| CVE-2024-38164 | CRIT 9.6 | microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. | 1.0% | — |
| CVE-2024-21341 | MED 6.8 | microsoft windows_10_1809 Windows Kernel Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-34121 | MED 4.1 | zoom rooms Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. | 1.0% | — |
| CVE-2023-20014 | HIGH 7.5 | cisco nexus_dashboard A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could | 1.0% | — |
| CVE-2022-23010 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in m | 1.0% | — |