58.412 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.412 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-0076 | MED 5.4 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 and R2; Windows 10, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a denial of se | 1.6% | — |
| CVE-2015-3214 | MED 6.9 | arista eos The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index. | 1.6% | — |
| CVE-2008-5230 | MED 6.8 | cisco ios The Temporal Key Integrity Protocol (TKIP) implementation in unspecified Cisco products and other vendors' products, as used in WPA and WPA2 on Wi-Fi networks, has insufficient countermeasures against certain crafted and replayed packets, which makes it easier | 1.6% | — |
| CVE-2025-62213 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | 1.6% | — |
| CVE-2024-43469 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-38114 | HIGH 8.8 | microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2023-21761 | HIGH 7.5 | microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability | 1.6% | — |
| CVE-2022-41122 | MED 6.5 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.6% | — |
| CVE-2013-1225 | HIGH 7.8 | cisco unified_customer_voice_portal Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, relate | 1.6% | — |
| CVE-2004-0186 | HIGH 7.2 | linux linux_kernel smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted. | 1.6% | — |
| CVE-2026-9155 | HIGH 8.8 | gnu sed OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation. | 1.6% | — |
| CVE-2026-21536 | CRIT 9.8 | microsoft devices_pricing_program Microsoft Devices Pricing Program Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2025-21364 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability | 1.6% | — |
| CVE-2022-20760 | HIGH 8.6 | cisco adaptive_security_appliance_software A vulnerability in the DNS inspection handler of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. Th | 1.6% | — |
| CVE-2021-28315 | HIGH 7.8 | microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2020-3168 | HIGH 7.5 | cisco nx-os A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through | 1.6% | — |
| CVE-2020-1160 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. | 1.6% | — |
| CVE-2014-1715 | HIGH 7.5 | google chrome Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors. | 1.6% | — |
| CVE-2014-0674 | MED 6.8 | cisco video_surveillance_operations_manager Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from | 1.6% | — |
| CVE-2023-31038 | HIGH 8.8 | apache log4cxx SQL injection in Log4cxx when using the ODBC appender to send log messages to a database. No fields sent to the database were properly escaped for SQL injection. This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx i | 1.6% | — |
| CVE-2023-25691 | CRIT 9.8 | apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. | 1.6% | — |
| CVE-2019-14215 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer. | 1.6% | — |
| CVE-2019-14214 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Service when deleting pages in a document that contains only one page by calling a "t.hidden = true" function. | 1.6% | — |
| CVE-2019-14210 | HIGH 7.5 | foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to the use of an invalid pointer copy, resulting from a destructed string object. | 1.6% | — |
| CVE-2019-13067 | CRIT 9.8 | f5 njs njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place. | 1.6% | — |