57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-20426 | CRIT 9.8 | ibm security_guardium IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313. | 1.0% | — |
| CVE-2020-17077 | HIGH 7.8 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2014-3631 | HIGH 7.2 | linux linux_kernel The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and syste | 1.0% | — |
| CVE-2009-4922 | MED 6.8 | cisco asa_5580 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (traceback) by establishing many IPsec L2L tunnels from remote peer IP addresse | 1.0% | — |
| CVE-2001-1384 | HIGH 7.2 | linux linux_kernel ptrace in Linux 2.2.x through 2.2.19, and 2.4.x through 2.4.9, allows local users to gain root privileges by running ptrace on a setuid or setgid program that itself calls an unprivileged program, such as newgrp. | 1.0% | — |
| CVE-2026-47301 | HIGH 8.8 | microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-44794 | CRIT 9.8 | dromara sa-token An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. | 1.0% | — |
| CVE-2023-20045 | MED 4.9 | cisco rv160_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulne | 1.0% | — |
| CVE-2022-47929 | MED 5.5 | debian debian_linux In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class | 1.0% | — |
| CVE-2022-22452 | HIGH 7.5 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. | 1.0% | — |
| CVE-2019-19793 | HIGH 8.8 | cyxtera appgate_sdp In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges. | 1.0% | — |
| CVE-2025-59284 | LOW 3.3 | microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | 1.0% | — |
| CVE-2023-36908 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-36598 | HIGH 7.8 | microsoft windows_10_1507 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-24935 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2022-21995 | HIGH 7.9 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-38975 | MED 6.5 | ibm security_guardium_key_lifecycle_manager IBM Tivoli Key Lifecycle Manager 3.0, 3.0.1, 4.0, and 4.1 could allow an authenticated user to to obtain sensitive information from a specially crafted HTTP request. IBM X-Force ID: 212780. | 1.0% | — |
| CVE-2021-28954 | HIGH 7.8 | bit_project bit In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository. | 1.0% | — |
| CVE-2021-26899 | HIGH 7.8 | microsoft windows_10 Windows UPnP Device Host Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-14356 | HIGH 7.8 | canonical ubuntu_linux A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. | 1.0% | — |
| CVE-2020-0648 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows RSoP Service Application improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a speci | 1.0% | — |
| CVE-2019-5590 | MED 6.1 | fortinet fortiweb The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form. | 1.0% | — |
| CVE-2025-49677 | HIGH 7.0 | microsoft windows_11_22h2 Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2024-39547 | HIGH 7.5 | juniper junos_containerized_routing_protocol_daemon An Improper Handling of Exceptional Conditions vulnerability in the rpd-server of Juniper Networks Junos OS and Junos OS Evolved within cRPD allows an unauthenticated network-based attacker sending crafted TCP traffic to the routing engine (RE) to cause a CPU- | 1.0% | — |
| CVE-2024-29217 | MED 4.6 | apache answer Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Answer.This issue affects Apache Answer: before 1.3.0. XSS attack when user changes personal website. A logged-in user, when modifying their personal | 1.0% | — |