57.977 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.977 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-0865 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-08 | 1.0% | — |
| CVE-2020-0800 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0797, CVE-2020-08 | 1.0% | — |
| CVE-2020-0797 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folder Service improperly handles file operations, aka 'Windows Work Folder Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0777, CVE-2020-0800, CVE-2020-08 | 1.0% | — |
| CVE-2017-5068 | HIGH 7.5 | google chrome Incorrect handling of picture ID in WebRTC in Google Chrome prior to 58.0.3029.96 for Mac, Windows, and Linux allowed a remote attacker to trigger a race condition via a crafted HTML page. | 1.0% | — |
| CVE-2009-2048 | LOW 3.5 | cisco crs Cross-site scripting (XSS) vulnerability in the Administration interface in Cisco Customer Response Solutions (CRS) before 7.0(1) SR2 in Cisco Unified Contact Center Express (aka CCX) server allows remote authenticated users to inject arbitrary web script or H | 1.0% | — |
| CVE-2008-4542 | LOW 3.5 | cisco unity Cross-site scripting (XSS) vulnerability in Cisco Unity 4.x before 4.2(1)ES162, 5.x before 5.0(1)ES56, and 7.x before 7.0(2)ES8 allows remote authenticated administrators to inject arbitrary web script or HTML by entering it in the database (aka data store). | 1.0% | — |
| CVE-1999-0400 | MED 4.6 | linux linux_kernel Denial of service in Linux 2.2.0 running the ldd command on a core file. | 1.0% | — |
| CVE-2025-64666 | HIGH 7.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-52434 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes following oops when accessing | 1.0% | — |
| CVE-2023-47539 | CRIT 9.8 | fortinet fortimail An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. | 1.0% | — |
| CVE-2023-41675 | MED 5.3 | fortinet fortios A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process vi | 1.0% | — |
| CVE-2023-31007 | NONE 0.0 | apache pulsar Improper Authentication vulnerability in Apache Software Foundation Apache Pulsar Broker allows a client to stay connected to a broker after authentication data expires if the client connected through the Pulsar Proxy when the broker is configured with authent | 1.0% | — |
| CVE-2022-21879 | MED 5.5 | microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-47241 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ethtool: strset: fix message length calculation Outer nest for ETHTOOL_A_STRSET_STRINGSETS is not accounted for. This may result in ETHTOOL_MSG_STRSET_GET producing a warning like: calc | 1.0% | — |
| CVE-2021-31376 | HIGH 7.5 | juniper junos An Improper Input Validation vulnerability in Packet Forwarding Engine manager (FXPC) process of Juniper Networks Junos OS allows an attacker to cause a Denial of Service (DoS) by sending specific DHCPv6 packets to the device and crashing the FXPC service. Con | 1.0% | — |
| CVE-2021-31374 | HIGH 7.5 | juniper junos On Juniper Networks Junos OS and Junos OS Evolved devices processing a specially crafted BGP UPDATE or KEEPALIVE message can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued receipt and processing of this m | 1.0% | — |
| CVE-2021-31351 | HIGH 7.5 | juniper junos An Improper Check for Unusual or Exceptional Conditions in packet processing on the MS-MPC/MS-MIC utilized by Juniper Networks Junos OS allows a malicious attacker to send a specific packet, triggering the MS-MPC/MS-MIC to reset, causing a Denial of Service (D | 1.0% | — |
| CVE-2021-0250 | HIGH 7.5 | juniper junos In segment routing traffic engineering (SRTE) environments where the BGP Monitoring Protocol (BMP) feature is enable, a vulnerability in the Routing Protocol Daemon (RPD) process of Juniper Networks Junos OS allows an attacker to send a specific crafted BGP up | 1.0% | — |
| CVE-2017-7644 | MED 6.5 | paloaltonetworks pan-os The Management Web Interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0.15, and 7.1.x before 7.1.9 allows remote authenticated users to obtain sensitive information by leveraging incorrect permission validation, aka PAN-SA-2017-0013 and PAN-705 | 1.0% | — |
| CVE-2016-10292 | MED 5.5 | linux linux_kernel A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Versions: Ke | 1.0% | — |
| CVE-2014-0691 | HIGH 7.3 | cisco webex_meetings_server Cisco WebEx Meetings Server before 1.1 uses meeting IDs with insufficient entropy, which makes it easier for remote attackers to bypass authentication and join arbitrary meetings without a password, aka Bug ID CSCuc79643. | 1.0% | — |
| CVE-2009-3001 | MED 4.9 | canonical ubuntu_linux The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket. | 1.0% | — |
| CVE-2025-64672 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2024-49117 | HIGH 8.8 | microsoft windows_11_22h2 Windows Hyper-V Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-30063 | MED 6.7 | microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1.0% | — |