58.015 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.015 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-36961 | MED 5.5 | microsoft windows_10 Windows Installer Denial of Service Vulnerability | 1.1% | — |
| CVE-2021-1540 | HIGH 8.1 | cisco staros Multiple vulnerabilities in the authorization process of Cisco ASR 5000 Series Software (StarOS) could allow an authenticated, remote attacker to bypass authorization and execute a subset of CLI commands on an affected device. For more information about these | 1.1% | — |
| CVE-2020-5914 | HIGH 7.5 | f5 big-ip_application_security_manager In BIG-IP ASM versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, undisclosed server cookie scenario may cause BD to restart under some circumstances. | 1.1% | — |
| CVE-2020-17097 | LOW 3.3 | microsoft windows_10 Windows Digital Media Receiver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2018-0015 | CRIT 9.8 | juniper appformix A malicious user with unrestricted access to the AppFormix application management platform may be able to access a Python debug console and execute system commands with root privilege. The AppFormix Agent exposes the debug console on a host where AppFormix Age | 1.1% | — |
| CVE-2017-6145 | HIGH 7.3 | f5 big-ip_access_policy_manager iControl REST in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe 12.0.0 through 12.1.2 and 13.0.0 includes a service to convert authorization BIGIPAuthCookie cookies to X-F5-Auth-Token tokens. This service does not properly | 1.1% | — |
| CVE-2026-69829 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Shell allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-23304 | HIGH 7.8 | nvidia nemo NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote | 1.1% | — |
| CVE-2022-25375 | MED 5.5 | debian debian_linux An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory. | 1.1% | — |
| CVE-2022-25265 | HIGH 7.8 | linux linux_kernel In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execution of bytes located in supposedly non-executable regions of | 1.1% | — |
| CVE-2019-1757 | MED 5.9 | cisco ios A vulnerability in the Cisco Smart Call Home feature of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data using an invalid certificate. The vulnerability is due to insufficient cert | 1.1% | — |
| CVE-2018-5510 | HIGH 7.5 | f5 big-ip_access_policy_manager On F5 BIG-IP 11.5.4 HF4-11.5.5, the Traffic Management Microkernel (TMM) may restart when processing a specific sequence of packets on IPv6 virtual servers. | 1.1% | — |
| CVE-2011-3309 | MED 4.3 | cisco 5500_series_adaptive_security_appliance Cisco Adaptive Security Appliances (ASA) 5500 series devices with software 8.2 through 8.4 process IKE requests despite a vpnclient mode configuration, which allows remote attackers to obtain potentially sensitive information by reading IKE responder traffic, | 1.1% | — |
| CVE-2002-1658 | MED 4.6 | apache http_server Buffer overflow in htdigest in Apache 1.3.26 and 1.3.27 may allow attackers to execute arbitrary code via a long user argument. NOTE: since htdigest is normally only locally accessible and not setuid or setgid, there are few attack vectors which would lead to | 1.1% | — |
| CVE-2024-43601 | HIGH 7.8 | microsoft visual_studio_code Visual Studio Code for Linux Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-25197 | MED 6.3 | apache fineract Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Software Foundation apache fineract. Authorized users may be able to exploit this for limited impact on components. This issue affects apache finera | 1.1% | — |
| CVE-2022-35821 | MED 4.4 | microsoft azure_sphere Azure Sphere Information Disclosure Vulnerability | 1.1% | — |
| CVE-2021-41016 | HIGH 7.8 | fortinet fortiextender_firmware A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands inc | 1.1% | — |
| CVE-2021-40440 | MED 5.4 | microsoft dynamics_365_business_central Microsoft Dynamics Business Central Cross-site Scripting Vulnerability | 1.1% | — |
| CVE-2021-32586 | HIGH 7.7 | fortinet fortimail An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests. | 1.1% | — |
| CVE-2020-4383 | MED 6.5 | ibm elastic_storage_server IBM Spectrum Scale for IBM Elastic Storage Server 5.3.0 through 5.3.5 could allow an authenticated user to cause a denial of service during deployment while configuring some of the network services. IBM X-Force ID: 179165. | 1.1% | — |
| CVE-2020-0731 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0691, CVE-2020-0719, CVE-2020-0720, CVE-2020- | 1.1% | — |
| CVE-2020-0635 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows when Windows fails to properly handle certain symbolic links, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0644. | 1.1% | — |
| CVE-2019-0973 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior. A locally authenticated attacker could run arbitrary code with elevated system | 1.1% | — |
| CVE-2017-14190 | MED 6.1 | fortinet fortios A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests. | 1.1% | — |