58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-43237 | HIGH 7.8 | microsoft windows_10 Windows Setup Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-3281 | HIGH 8.8 | cisco digital_network_architecture_center A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credenti | 1.0% | — |
| CVE-2020-24346 | HIGH 7.8 | f5 njs njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. | 1.0% | — |
| CVE-2019-1272 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system, aka 'Wi | 1.0% | — |
| CVE-2019-1010232 | MED 6.5 | juniper libslax Juniper juniper/libslax libslax latest version (as of commit 084ddf6ab4a55b59dfa9a53f9c5f14d192c4f8e5 Commits on Sep 1, 2018) is affected by: Buffer Overflow. The impact is: remote dos. The component is: slaxlexer.c:601(funtion:slaxGetInput). The attack vector | 1.0% | — |
| CVE-2017-5039 | HIGH 7.8 | debian debian_linux A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | 1.0% | — |
| CVE-2013-1275 | HIGH 7.0 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.0% | — |
| CVE-2013-1265 | HIGH 7.0 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.0% | — |
| CVE-2013-1253 | HIGH 7.0 | microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently | 1.0% | — |
| CVE-2005-4605 | LOW 2.1 | linux linux_kernel The procfs code (proc_misc.c) in Linux 2.6.14.3 and other versions before 2.6.15 allows attackers to read sensitive kernel memory via unspecified vectors in which a signed value is added to an unsigned value. | 1.0% | — |
| CVE-2024-49041 | MED 4.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2024-22233 | HIGH 7.5 | vmware spring_framework In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the ap | 1.0% | — |
| CVE-2023-21695 | HIGH 7.5 | microsoft windows_10 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-46763 | HIGH 8.8 | trueconf server A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code. | 1.0% | — |
| CVE-2021-39033 | MED 6.5 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5 and 6.1.0.0 through 6.1.1.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in | 1.0% | — |
| CVE-2021-31361 | MED 5.3 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with Improper Handling of Exceptional Conditions in Juniper Networks Junos OS on QFX Series and PTX Series allows an unauthenticated network based attacker to cause increased FPC CP | 1.0% | — |
| CVE-2015-6306 | HIGH 7.2 | cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947. | 1.0% | — |
| CVE-2015-6263 | MED 6.3 | cisco ios The RADIUS client implementation in Cisco IOS 15.4(3)M2.2, when a shared RADIUS secret is configured, allows remote RADIUS servers to cause a denial of service (device reload) via malformed answers, aka Bug ID CSCuu59324. | 1.0% | — |
| CVE-2026-69443 | HIGH 7.5 | microsoft windows_10_1809 Out-of-bounds read in Windows Device Health Attestation (DHA) allows an unauthorized attacker to disclose information over a network. | 1.0% | — |
| CVE-2025-59254 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2022-20912 | MED 4.7 | cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1.0% | — |
| CVE-2022-20911 | MED 4.7 | cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1.0% | — |
| CVE-2022-20904 | MED 4.7 | cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1.0% | — |
| CVE-2022-20903 | MED 4.7 | cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1.0% | — |
| CVE-2022-20902 | MED 4.7 | cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe | 1.0% | — |