IT
58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.046 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-0156 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle ob 1.1%
CVE-2025-21381 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1.1%
CVE-2023-6792 MED 5.5 paloaltonetworks pan-os An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall. 1.1%
CVE-2022-31660 HIGH 7.8 vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. 1.1%
CVE-2021-40767 MED 5.5 adobe character_animator Adobe Character Animator version 4.4 (and earlier) is affected by an Access of Memory Location After End of Buffer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application deni 1.1%
CVE-2020-1995 MED 4.9 paloaltonetworks pan-os A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by r 1.1%
CVE-2018-20733 HIGH 7.5 sas web_infrastructure_platform BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. 1.1%
CVE-2026-77484 HIGH 8.8 microsoft sql_server_2019 Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. 1.1%
CVE-2025-53153 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-53148 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-53138 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.1%
CVE-2025-50157 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.1%
CVE-2020-15941 MED 5.4 fortinet forticlient_endpoint_management_server A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment 1.1%
CVE-2024-38053 HIGH 8.8 microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability 1.1%
CVE-2021-26866 HIGH 7.1 microsoft windows_10 Windows Update Service Elevation of Privilege Vulnerability 1.1%
CVE-2020-26944 CRIT 9.8 aptean product_configurator An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely. 1.1%
CVE-2018-1036 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows S 1.1%
CVE-2018-0057 MED 6.1 juniper junos On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address binding in 1.1%
CVE-2017-6130 HIGH 7.4 f5 ssl_intercept_iapp F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic. 1.1%
CVE-2014-3793 MED 5.8 vmware esxi VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of 1.1%
CVE-2003-1423 MED 5.0 petitforum petitforum Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. 1.1%
CVE-2025-21177 HIGH 8.7 microsoft dynamics_365_sales Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2023-29337 HIGH 7.1 microsoft nuget NuGet Client Remote Code Execution Vulnerability 1.1%
CVE-2023-25621 MED 6.5 apache sling_i18n Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it al 1.1%
CVE-2023-21808 HIGH 7.8 microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability 1.1%