IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-1000 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0913, CVE-2020-1003, CVE-2020-1027. 0.9%
CVE-2020-0985 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory, aka 'Windows Update Stack Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0996. 0.9%
CVE-2019-5006 MED 5.5 foxitsoftware foxit_reader An issue was discovered in Foxit Reader and PhantomPDF before 9.4 on Windows. It is a NULL pointer dereference during PDF parsing. 0.9%
CVE-2017-2317 HIGH 8.6 juniper northstar_controller A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading t 0.9%
CVE-2016-2854 HIGH 7.8 linux linux_kernel The aufs module for the Linux kernel 3.x and 4.x does not properly maintain POSIX ACL xattr data, which allows local users to gain privileges by leveraging a group-writable setgid directory. 0.9%
CVE-2015-6400 MED 4.3 cisco emergency_responder Multiple cross-site scripting (XSS) vulnerabilities in Cisco Emergency Responder 10.5(1a) allow remote attackers to inject arbitrary web script or HTML via unspecified fields, aka Bug ID CSCuv25547. 0.9%
CVE-2025-59248 HIGH 7.5 microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. 1.0%
CVE-2024-28896 HIGH 7.5 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2024-26184 MED 6.8 microsoft windows_10_21h2 Secure Boot Security Feature Bypass Vulnerability 1.0%
CVE-2023-36557 HIGH 7.8 microsoft windows_10_1507 PrintHTML API Remote Code Execution Vulnerability 1.0%
CVE-2023-20080 HIGH 8.6 cisco ios A vulnerability in the IPv6 DHCP version 6 (DHCPv6) relay and server features of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. This vulnerability is due to insufficient validation 1.0%
CVE-2020-3549 HIGH 8.1 cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due 1.0%
CVE-2020-0707 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows IME improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows IME Elevation of Privilege Vulnerability'. 1.0%
CVE-2020-0704 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Wireless Network Manager improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Wireless Network Manager Elevati 1.0%
CVE-2014-3302 MED 5.8 cisco webex_meetings_server user.php in Cisco WebEx Meetings Server 1.5(.1.131) and earlier does not properly implement the token timer for authenticated encryption, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCuj81708. 1.0%
CVE-2002-1106 HIGH 7.5 cisco vpn_client Cisco Virtual Private Network (VPN) Client software 2.x.x, and 3.x before 3.5.1C, does not properly verify that certificate DN fields match those of the certificate from the VPN Concentrator, which allows remote attackers to conduct man-in-the-middle attacks. 1.0%
CVE-2026-67390 MED 6.5 microsoft sql_server_2017 Buffer over-read in SQL Server allows an authorized attacker to disclose information over a network. 1.0%
CVE-2026-67383 MED 6.5 microsoft sql_server_2025 Generation of error message containing sensitive information in SQL Server allows an authorized attacker to disclose information over a network. 1.0%
CVE-2025-26630 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Access allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-24057 HIGH 7.8 microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally. 1.0%
CVE-2024-38164 CRIT 9.6 microsoft groupme An improper access control vulnerability in GroupMe allows an a unauthenticated attacker to elevate privileges over a network by convincing a user to click on a malicious link. 1.0%
CVE-2024-21341 MED 6.8 microsoft windows_10_1809 Windows Kernel Remote Code Execution Vulnerability 1.0%
CVE-2023-34121 MED 4.1 zoom rooms Improper input validation in the Zoom for Windows, Zoom Rooms, Zoom VDI Windows Meeting clients before 5.14.0 may allow an authenticated user to potentially enable an escalation of privilege via network access. 1.0%
CVE-2023-20014 HIGH 7.5 cisco nexus_dashboard A vulnerability in the DNS functionality of Cisco Nexus Dashboard Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the improper processing of DNS requests. An attacker could 1.0%
CVE-2022-23010 HIGH 7.5 f5 big-ip_access_policy_manager On BIG-IP versions 16.x before 16.1.0, 15.1.x before 15.1.4.1, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, when a FastL4 profile and an HTTP profile are configured on a virtual server, undisclosed requests can cause an increase in m 1.0%