57.977 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.977 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2014-9870 | HIGH 7.8 | google android The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, a | 1.0% | — |
| CVE-2012-3375 | MED 4.9 | linux linux_kernel The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted | 1.0% | — |
| CVE-2023-52798 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix dfs radar event locking The ath11k active pdevs are protected by RCU but the DFS radar event handling code calling ath11k_mac_get_ar_by_pdev_id() was not marked as a read-s | 1.0% | — |
| CVE-2023-42505 | MED 4.3 | apache superset An authenticated user with read permissions on database connections metadata could potentially access sensitive information such as the connection's username. This issue affects Apache Superset before 3.0.0. | 1.0% | — |
| CVE-2023-36436 | HIGH 7.8 | microsoft windows_10_1507 Windows MSHTML Platform Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-41746 | CRIT 9.1 | trendmicro apex_one A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to l | 1.0% | — |
| CVE-2022-28670 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 1.0% | — |
| CVE-2021-38633 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2013-2852 | MED 6.9 | canonical ubuntu_linux Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format strin | 1.0% | — |
| CVE-2025-21331 | HIGH 7.3 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2024-37968 | HIGH 7.5 | microsoft windows_server_2008 Windows DNS Spoofing Vulnerability | 1.0% | — |
| CVE-2023-33153 | MED 6.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-27523 | MED 5.0 | apache superset Improper data authorization check on Jinja templated queries in Apache Superset up to and including 2.1.0 allows for an authenticated user to issue queries on database tables they may not have access to. | 1.0% | — |
| CVE-2022-24908 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.0% | — |
| CVE-2022-24907 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.1.0.52543. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.0% | — |
| CVE-2021-36950 | MED 5.4 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2021-36946 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1.0% | — |
| CVE-2021-22095 | MED 6.5 | vmware spring_advanced_message_queuing_protocol In Spring AMQP versions 2.2.0 - 2.2.19 and 2.3.0 - 2.3.11, the Spring AMQP Message object, in its toString() method, will create a new String object from the message body, regardless of its size. This can cause an OOM Error with a large message | 1.0% | — |
| CVE-2021-0232 | HIGH 7.4 | fedoraproject fedora An authentication bypass vulnerability in the Juniper Networks Paragon Active Assurance Control Center may allow an attacker with specific information about the deployment to mimic an already registered Test Agent and access its configuration including associa | 1.0% | — |
| CVE-2020-5894 | HIGH 8.1 | f5 nginx_controller On versions 3.0.0-3.3.0, the NGINX Controller webserver does not invalidate the server-side session token after users log out. | 1.0% | — |
| CVE-2020-3502 | MED 4.1 | cisco webex_meetings Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters r | 1.0% | — |
| CVE-2020-3501 | MED 4.1 | cisco webex_meetings Multiple vulnerabilities in the user interface of Cisco Webex Meetings Desktop App could allow an authenticated, remote attacker to obtain restricted information from other Webex users. These vulnerabilities are due to improper input validation of parameters r | 1.0% | — |
| CVE-2020-3377 | MED 6.3 | cisco data_center_network_manager A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplie | 1.0% | — |
| CVE-2020-1418 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Diagnostics Execution Service fails to properly sanitize input, leading to an unsecure library-loading behavior, aka 'Windows Diagnostics Hub Elevation of Privilege Vulnerability'. This CVE ID is | 1.0% | — |
| CVE-2020-1029 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Connected User Experiences and Telemetry Service improperly handles file operations, aka 'Connected User Experiences and Telemetry Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE | 1.0% | — |