58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-28676 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.1% | — |
| CVE-2022-28675 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.1% | — |
| CVE-2022-28674 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.1% | — |
| CVE-2022-28673 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.1% | — |
| CVE-2022-28671 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.1% | — |
| CVE-2022-28669 | HIGH 7.8 | foxit pdf_editor This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. | 1.1% | — |
| CVE-2019-12666 | MED 6.7 | cisco ios_xe A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain co | 1.1% | — |
| CVE-2019-0019 | HIGH 7.5 | juniper junos When BGP tracing is enabled an incoming BGP message may cause the Junos OS routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, repeated crashes can result in an extended DoS condition. Affected releases are Juniper Net | 1.1% | — |
| CVE-2012-4360 | MED 4.3 | google mod_pagespeed Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.10.19.1 through 0.10.22.4 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.1% | — |
| CVE-2025-21210 | MED 4.2 | microsoft windows_10_1507 Windows BitLocker Information Disclosure Vulnerability | 1.1% | — |
| CVE-2025-21186 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-26579 | CRIT 9.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.11.0, the attackers can bypass using malicious parameters. Users are advised to upgrade to Apache InLong's 1.12.0 or cherry-pick [1], [2 | 1.1% | — |
| CVE-2021-39052 | CRIT 9.8 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523. | 1.1% | — |
| CVE-2021-26873 | HIGH 7.0 | microsoft windows_10 Windows User Profile Service Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2021-1581 | MED 6.5 | cisco application_policy_infrastructure_controller Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more informa | 1.1% | — |
| CVE-2020-16964 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16963 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16962 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16959 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-16958 | HIGH 7.8 | microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-1070 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An | 1.1% | — |
| CVE-2025-29792 | HIGH 7.3 | microsoft 365_apps Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2024-21395 | HIGH 8.2 | microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | 1.1% | — |
| CVE-2021-1266 | MED 4.3 | cisco managed_services_accelerator A vulnerability in the REST API of Cisco Managed Services Accelerator (MSX) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to the way that the affected software logs ce | 1.1% | — |
| CVE-2017-5038 | MED 6.3 | debian debian_linux Chrome Apps in Google Chrome prior to 57.0.2987.98 for Linux, Windows, and Mac had a use after free bug in GuestView, which allowed a remote attacker to perform an out of bounds memory read via a crafted Chrome extension. | 1.1% | — |