58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2011-2059 | MED 5.0 | cisco ios The ipv6 component in Cisco IOS before 15.1(4)M1.3 allows remote attackers to conduct fingerprinting attacks and obtain potentially sensitive information about the presence of the IOS operating system via an ICMPv6 Echo Request packet containing a Hop-by-Hop ( | 1.6% | — |
| CVE-2008-3671 | MED 5.0 | acronis true_image_echo_server Acronis True Image Echo Server 9.x build 8072 on Linux does not properly encrypt backups to an FTP server, which allows remote attackers to obtain sensitive information. NOTE: the provenance of this information is unknown; the details are obtained solely from | 1.6% | — |
| CVE-1999-0839 | HIGH 7.2 | microsoft ie Windows NT Task Scheduler installed with Internet Explorer 5 allows a user to gain privileges by modifying the job after it has been scheduled. | 1.6% | — |
| CVE-1999-0701 | HIGH 7.2 | microsoft windows_nt After an unattended installation of Windows NT 4.0, an installation file could include sensitive information such as the local Administrator password. | 1.6% | — |
| CVE-2023-24936 | HIGH 7.5 | microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2022-23256 | HIGH 8.1 | microsoft azure_data_explorer Azure Data Explorer Spoofing Vulnerability | 1.6% | — |
| CVE-2021-22056 | HIGH 7.5 | vmware identity_manager VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. | 1.6% | — |
| CVE-2014-3366 | MED 6.5 | cisco unified_communications_manager SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089. | 1.6% | — |
| CVE-2014-3275 | MED 6.5 | cisco identity_services_engine_software SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCul21337. | 1.6% | — |
| CVE-2023-35384 | MED 5.4 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2022-41081 | HIGH 8.1 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-37965 | MED 5.9 | microsoft windows_10 Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability | 1.6% | — |
| CVE-2022-26929 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26233 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26224 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26223 | HIGH 7.2 | microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-31184 | MED 5.5 | microsoft windows_10 Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability | 1.6% | — |
| CVE-2019-4614 | MED 6.5 | ibm mq IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639. | 1.6% | — |
| CVE-2019-1375 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | 1.6% | — |
| CVE-2019-12632 | HIGH 7.5 | cisco finesse A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerability exists because the affected system does not properly val | 1.6% | — |
| CVE-2019-0876 | MED 5.5 | microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2016-7391 | HIGH 7.8 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array bounds ch | 1.6% | — |
| CVE-2025-22224 | CRIT 9.3 | vmware cloud_foundation VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual mach | 1.6% | |
| CVE-2025-21334 | HIGH 7.8 | microsoft windows_10_21h2 Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | 1.6% | |
| CVE-2021-42008 | HIGH 7.8 | debian debian_linux The decode_data function in drivers/net/hamradio/6pack.c in the Linux kernel before 5.13.13 has a slab out-of-bounds write. Input from a process that has the CAP_NET_ADMIN capability can lead to root access. | 1.6% | — |