57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0445 | HIGH 7.0 | google android An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 1.0% | — |
| CVE-2020-3400 | HIGH 8.8 | cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to utilize parts of the web UI for which they are not authorized.The vulnerability is due to insufficient authorization of web UI access requests. An a | 1.0% | — |
| CVE-2020-1109 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Update Stack fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; | 1.0% | — |
| CVE-2019-15956 | HIGH 8.8 | cisco asyncos A vulnerability in the web management interface of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an authenticated, remote attacker to perform an unauthorized system reset on an affected device. The vulnerability is due to improper a | 1.0% | — |
| CVE-2015-6408 | MED 6.8 | cisco unity_connection Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux24578. | 1.0% | — |
| CVE-2015-6405 | MED 6.8 | cisco emergency_responder Cross-site request forgery (CSRF) vulnerability in Cisco Emergency Responder 10.5(1) and 10.5(1a) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv26501. | 1.0% | — |
| CVE-2015-4281 | MED 6.8 | cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server 2.5 MR1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCus56150 and CSCus56146. | 1.0% | — |
| CVE-2023-36420 | HIGH 7.8 | microsoft odbc_driver_for_sql_server Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36417 | HIGH 7.8 | microsoft ole_db_driver_for_sql_server Microsoft SQL OLE DB Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-25195 | HIGH 8.1 | apache fineract Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache Fineract. Authorized users with limited permissions can gain access to server and may be able to use server for any outbound traffic. This issue affects Apache Fineract: fr | 1.0% | — |
| CVE-2021-29784 | MED 4.3 | ibm i2_analyze IBM i2 Analyze 4.3.0, 4.3.1, and 4.3.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 20316 | 1.0% | — |
| CVE-2021-20552 | MED 4.3 | ibm sterling_file_gateway IBM Sterling File Gateway 6.0.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Forc | 1.0% | — |
| CVE-2018-6755 | HIGH 7.2 | mcafee true_key Weak Directory Permission Vulnerability in Microsoft Windows client in McAfee True Key (TK) 5.1.230.7 and earlier allows local users to execute arbitrary code via specially crafted malware. | 1.0% | — |
| CVE-2017-12271 | HIGH 8.8 | cisco spa300_firmware A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could | 1.0% | — |
| CVE-2015-3293 | MED 4.0 | fortinet fortimail FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command. | 1.0% | — |
| CVE-2014-0740 | MED 6.8 | cisco unified_communications_manager Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the | 1.0% | — |
| CVE-2007-2038 | MED 6.1 | cisco 2000_wireless_lan_controller The Network Processing Unit (NPU) in the Cisco Wireless LAN Controller (WLC) before 3.2.193.5, 4.0.x before 4.0.206.0, and 4.1.x allows remote attackers on a local wireless network to cause a denial of service (loss of packet forwarding) via (1) crafted SNAP p | 1.0% | — |
| CVE-2026-78523 | MED 5.9 | microsoft windows_10_1607 Use after free in Windows DNS allows an unauthorized attacker to deny service over a network. | 1.0% | — |
| CVE-2024-47693 | MED 6.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: IB/core: Fix ib_cache_setup_one error flow cleanup When ib_cache_update return an error, we exit ib_cache_setup_one instantly with no proper cleanup, even though before this we had already s | 1.0% | — |
| CVE-2024-41151 | HIGH 8.8 | apache hertzbeat Deserialization of Untrusted Data vulnerability in Apache HertzBeat. This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat: before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the iss | 1.0% | — |
| CVE-2024-38010 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37989 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37988 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37986 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |
| CVE-2024-37974 | HIGH 8.0 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 1.0% | — |