58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2016-1008 | HIGH 8.4 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privilege | 1.1% | — |
| CVE-2012-2856 | HIGH 7.5 | google chrome The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-o | 1.1% | — |
| CVE-2026-50515 | CRIT 9.9 | microsoft azure_service_bus Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-49735 | HIGH 8.1 | microsoft windows_server_2012 Use after free in Windows KDC Proxy Service (KPSSVC) allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-20309 | CRIT 10.0 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, wh | 1.1% | — |
| CVE-2024-43574 | HIGH 8.3 | microsoft windows_10_21h2 Microsoft Speech Application Programming Interface (SAPI) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21783 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-1278 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1303. | 1.1% | — |
| CVE-2018-15387 | CRIT 9.8 | cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by su | 1.1% | — |
| CVE-2017-3833 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb959 | 1.1% | — |
| CVE-2026-66808 | HIGH 8.8 | microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2026-44815 | CRIT 9.8 | microsoft windows_10_1607 Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2026-20922 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 1.1% | — |
| CVE-2026-20854 | HIGH 7.5 | microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2022-24511 | MED 5.5 | microsoft 365_apps Microsoft Office Word Tampering Vulnerability | 1.1% | — |
| CVE-2022-20823 | HIGH 8.6 | cisco nexus_3016_firmware A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of speci | 1.1% | — |
| CVE-2022-20733 | MED 5.3 | cisco identity_services_engine A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Asser | 1.1% | — |
| CVE-2021-40130 | MED 4.9 | cisco common_services_platform_collector A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog co | 1.1% | — |
| CVE-2021-36168 | MED 6.5 | fortinet fortiportal A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET r | 1.1% | — |
| CVE-2021-22044 | HIGH 7.5 | vmware spring_cloud_openfeign In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@Reques | 1.1% | — |
| CVE-2020-28588 | MED 5.5 | linux linux_kernel An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in | 1.1% | — |
| CVE-2019-1167 | MED 4.1 | microsoft powershell_core A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | 1.1% | — |
| CVE-2007-1000 | HIGH 7.2 | linux linux_kernel The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference. | 1.1% | — |
| CVE-2026-41606 | MED 5.3 | apache thrift Uncontrolled Recursion vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. | 1.1% | — |
| CVE-2021-43067 | HIGH 8.3 | fortinet fortiauthenticator A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and below, version 6.1.2 and below, version 6.0.7 to 6.0.1 allows attacker to duplicate a target LDAP user 2 facto | 1.1% | — |