58.165 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.165 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2012-4144 | MED 4.3 | opera opera_browser Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted | 1.2% | — |
| CVE-2025-27744 | HIGH 7.8 | microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2025-26646 | HIGH 8.0 | microsoft .net External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. | 1.2% | — |
| CVE-2002-0725 | MED 5.5 | microsoft windows_2000 NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. | 1.2% | — |
| CVE-2026-77494 | HIGH 7.5 | microsoft windows_10_1607 Access of resource using incompatible type ('type confusion') in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69631 | HIGH 7.5 | microsoft windows_10_1607 Integer overflow or wraparound in Windows DNS allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69588 | HIGH 7.5 | microsoft windows_11_23h2 Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2025-39682 | CRIT 9.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next recor | 1.2% | |
| CVE-2020-10866 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC. | 1.2% | — |
| CVE-2019-12623 | MED 4.3 | cisco enterprise_network_functions_virtualization_infrastructure A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to th | 1.2% | — |
| CVE-2018-15406 | MED 6.1 | cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vu | 1.2% | — |
| CVE-2017-0328 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product | 1.2% | — |
| CVE-2013-1120 | MED 6.8 | cisco unity_express Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910. | 1.2% | — |
| CVE-2026-69881 | HIGH 7.5 | microsoft windows_10_1809 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2026-69587 | HIGH 7.5 | microsoft windows_11_23h2 Null pointer dereference in Windows IKE Extension allows an unauthorized attacker to deny service over a network. | 1.2% | — |
| CVE-2022-46651 | MED 6.5 | apache airflow Apache Airflow, versions before 2.6.3, is affected by a vulnerability that allows an unauthorized actor to gain access to sensitive information in Connection edit view. This vulnerability is considered low since it requires someone with access to Connection re | 1.2% | — |
| CVE-2021-1670 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1.2% | — |
| CVE-2021-1663 | MED 5.5 | microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability | 1.2% | — |
| CVE-2021-1637 | MED 5.5 | microsoft windows_10 Windows DNS Query Information Disclosure Vulnerability | 1.2% | — |
| CVE-2019-14686 | HIGH 7.8 | trendmicro antivirus_\+_security_2019 A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, l | 1.2% | — |
| CVE-2017-6670 | MED 6.1 | cisco unified_communications_domain_manager A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8 | 1.2% | — |
| CVE-2017-6604 | MED 6.1 | cisco unified_computing_system A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC | 1.2% | — |
| CVE-2025-54472 | HIGH 7.5 | apache brpc Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows attackers to crash the service via network. Root Cause: In the bRPC Redis protocol parser code, memory for arrays or strings of corresponding | 1.2% | — |
| CVE-2021-0205 | MED 5.8 | juniper junos When the "Intrusion Detection Service" (IDS) feature is configured on Juniper Networks MX series with a dynamic firewall filter using IPv6 source or destination prefix, it may incorrectly match the prefix as /32, causing the filter to block unexpected traffic. | 1.2% | — |
| CVE-2020-5897 | HIGH 8.8 | f5 big-ip_access_policy_manager In versions 7.1.5-7.1.9, there is use-after-free memory vulnerability in the BIG-IP Edge Client Windows ActiveX component. | 1.2% | — |