58.046 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.046 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0156 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows 7, Windows 8.1, Windows RT 8.1, Windows 10, Windows Server 2008 R2, Windows Server 2012, Windows Server 2012 R2, and Windows Server 2016 when the Microsoft Graphics Component fails to properly handle ob | 1.1% | — |
| CVE-2025-21381 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-6792 | MED 5.5 | paloaltonetworks pan-os An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewall. | 1.1% | — |
| CVE-2022-31660 | HIGH 7.8 | vmware access_connector VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A malicious actor with local access can escalate privileges to 'root'. | 1.1% | — |
| CVE-2021-40767 | MED 5.5 | adobe character_animator Adobe Character Animator version 4.4 (and earlier) is affected by an Access of Memory Location After End of Buffer vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application deni | 1.1% | — |
| CVE-2020-1995 | MED 4.9 | paloaltonetworks pan-os A NULL pointer dereference vulnerability in Palo Alto Networks PAN-OS allows an authenticated administrator to send a request that causes the rasmgr daemon to crash. Repeated attempts to send this request result in denial of service to all PAN-OS services by r | 1.1% | — |
| CVE-2018-20733 | HIGH 7.5 | sas web_infrastructure_platform BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. | 1.1% | — |
| CVE-2026-77484 | HIGH 8.8 | microsoft sql_server_2019 Deserialization of untrusted data in SQL Server allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-53153 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-53148 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-53138 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-50157 | MED 5.7 | microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2020-15941 | MED 5.4 | fortinet forticlient_endpoint_management_server A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject directory traversal character sequences to add/delete the files of the server via the name parameter of Deployment | 1.1% | — |
| CVE-2024-38053 | HIGH 8.8 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-26866 | HIGH 7.1 | microsoft windows_10 Windows Update Service Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2020-26944 | CRIT 9.8 | aptean product_configurator An issue was discovered in Aptean Product Configurator 4.61.0000 on Windows. A Time based SQL injection affects the nameTxt parameter on the main login page (aka cse?cmd=LOGIN). This can be exploited directly, and remotely. | 1.1% | — |
| CVE-2018-1036 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows S | 1.1% | — |
| CVE-2018-0057 | MED 6.1 | juniper junos On MX Series and M120/M320 platforms configured in a Broadband Edge (BBE) environment, subscribers logging in with DHCP Option 50 to request a specific IP address will be assigned the requested IP address, even if there is a static MAC to IP address binding in | 1.1% | — |
| CVE-2017-6130 | HIGH 7.4 | f5 ssl_intercept_iapp F5 SSL Intercept iApp 1.5.0 - 1.5.7 and SSL Orchestrator 2.0 is vulnerable to a Server-Side Request Forgery (SSRF) attack when deployed using the Dynamic Domain Bypass (DDB) feature feature plus SNAT Auto Map option for egress traffic. | 1.1% | — |
| CVE-2014-3793 | MED 5.8 | vmware esxi VMware Tools in VMware Workstation 10.x before 10.0.2, VMware Player 6.x before 6.0.2, VMware Fusion 6.x before 6.0.3, and VMware ESXi 5.0 through 5.5, when a Windows 8.1 guest OS is used, allows guest OS users to gain guest OS privileges or cause a denial of | 1.1% | — |
| CVE-2003-1423 | MED 5.0 | petitforum petitforum Petitforum stores the liste.txt data file under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as e-mail addresses and encrypted passwords. | 1.1% | — |
| CVE-2025-21177 | HIGH 8.7 | microsoft dynamics_365_sales Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2023-29337 | HIGH 7.1 | microsoft nuget NuGet Client Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-25621 | MED 6.5 | apache sling_i18n Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it al | 1.1% | — |
| CVE-2023-21808 | HIGH 7.8 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.1% | — |