IT
58.306 CVE tracked
789 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.306 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-0296 HIGH 7.8 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to elevate privilege when tdx.sys fails to check the lengt 1.3% —
CVE-2011-4023 HIGH 7.8 cisco nexus_2148t_fex_switch Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682. 1.3% —
CVE-2025-21326 HIGH 7.8 microsoft windows_server_2022_23h2 Internet Explorer Remote Code Execution Vulnerability 1.3% —
CVE-2024-21328 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability 1.3% —
CVE-2021-28660 HIGH 8.8 debian debian_linux rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (un 1.3% —
CVE-2021-1588 HIGH 8.6 cisco nx-os A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improp 1.3% —
CVE-2020-0617 MED 6.0 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'. 1.3% —
CVE-2021-21233 HIGH 8.8 debian debian_linux Heap buffer overflow in ANGLE in Google Chrome on Windows prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. 1.3% —
CVE-2021-0211 CRIT 10.0 juniper junos An improper check for unusual or exceptional conditions in Juniper Networks Junos OS and Junos OS Evolved Routing Protocol Daemon (RPD) service allows an attacker to send a valid BGP FlowSpec message thereby causing an unexpected change in the route advertisem 1.3% —
CVE-2019-1922 MED 5.3 cisco ip_conference_phone_7832_firmware A vulnerability in Cisco SIP IP Phone Software for Cisco IP Phone 7800 Series and 8800 Series could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected phone. The vulnerability is due to insufficient validation 1.3% —
CVE-2019-15791 HIGH 7.1 canonical ubuntu_linux In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the b 1.3% —
CVE-2013-5525 MED 6.5 cisco identity_services_engine_software SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502. 1.3% —
CVE-2002-1098 HIGH 7.5 cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.3, adds an "HTTPS on Public Inbound (XML-Auto)(forward/in)" rule but sets the protocol to "ANY" when the XML filter configuration is enabled, which ultimately allows arbitrary traffic to pass through the co 1.3% —
CVE-2002-1096 HIGH 7.5 cisco vpn_3000_concentrator_series_software Cisco VPN 3000 Concentrator 2.2.x, and 3.x before 3.5.1, allows restricted administrators to obtain user passwords that are stored in plaintext in HTML source code. 1.3% —
CVE-2025-62549 HIGH 8.8 microsoft windows_10_1607 Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 1.3% —
CVE-2024-38264 MED 5.9 microsoft windows_11_22h2 Microsoft Virtual Hard Disk (VHDX) Denial of Service Vulnerability 1.3% —
CVE-2023-38155 HIGH 7.0 microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability 1.3% —
CVE-2023-20024 HIGH 8.6 cisco business_250-16p-2g_firmware Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with root privileges on an affected 1.3% —
CVE-2020-19692 CRIT 9.8 f5 njs Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attacker to execute arbitrary code via the njs_module_read in the njs_module.c file. 1.3% —
CVE-2019-1339 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles hard links, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1315, CVE-2019-1342. 1.3% —
CVE-2017-3842 MED 5.3 cisco intrusion_prevention_system_device_manager A vulnerability in the web-based management interface of the Cisco Intrusion Prevention System Device Manager (IDM) could allow an unauthenticated, remote attacker to view sensitive information stored in certain HTML comments. More Information: CSCuh91455. Kno 1.3% —
CVE-2016-8737 HIGH 8.8 apache brooklyn In Apache Brooklyn before 0.10.0, the REST server is vulnerable to cross-site request forgery (CSRF), which could permit a malicious web site to produce a link which, if clicked whilst a user is logged in to Brooklyn, would cause the server to execute the atta 1.3% —
CVE-2015-0683 MED 4.0 cisco unified_communications_domain_manager Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744. 1.3% —
CVE-2015-0680 MED 4.0 cisco unified_callmanager Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439. 1.3% —
CVE-2014-8007 MED 4.0 cisco prime_infrastructure Cisco Prime Infrastructure allows remote authenticated users to read device-discovery passwords by examining the HTML source code of the Quick Discovery options page, aka Bug ID CSCum00019. 1.3% —