IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2025-61787 HIGH 8.1 deno deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a b 2.1% —
CVE-2024-20652 HIGH 8.1 microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability 2.1% —
CVE-2020-29019 MED 5.3 fortinet fortiweb A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to crash the httpd daemon thread by sending a request with a crafted cookie header. 2.1% —
CVE-2020-10863 HIGH 7.5 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine. 2.1% —
CVE-2020-10860 HIGH 7.5 avast antivirus An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Denial of Service of the Avast Service (AvastSvc.exe). 2.1% —
CVE-2019-4545 HIGH 7.5 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877. 2.1% —
CVE-2019-0798 MED 6.1 microsoft lync_server A spoofing vulnerability exists when a Lync Server or Skype for Business Server does not properly sanitize a specially crafted request, aka 'Skype for Business and Lync Spoofing Vulnerability'. 2.1% —
CVE-2018-4316 HIGH 8.8 apple icloud A memory corruption issue was addressed with improved state management. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. 2.1% —
CVE-2017-16994 MED 5.5 linux linux_kernel The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call. 2.1% —
CVE-2025-27486 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2.1% —
CVE-2025-27485 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2.1% —
CVE-2025-21174 HIGH 7.5 microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. 2.1% —
CVE-2022-41058 HIGH 7.5 microsoft windows_10 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.1% —
CVE-2022-41056 HIGH 7.5 microsoft windows_10 Network Policy Server (NPS) RADIUS Protocol Denial of Service Vulnerability 2.1% —
CVE-2023-28267 MED 6.5 microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability 2.1% —
CVE-2025-54539 CRIT 9.8 apache activemq_nms_amqp A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all versions of Apache ActiveMQ NMS AMQP up to and including 2.3.0, when establishing connections to untrusted AMQP servers. Malicious servers 2.1% —
CVE-2023-34989 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1% —
CVE-2023-34988 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1% —
CVE-2023-34987 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1% —
CVE-2023-34986 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1% —
CVE-2023-34985 HIGH 8.8 fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req 2.1% —
CVE-2020-1056 MED 5.4 microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based attack scenario, an attack 2.1% —
CVE-2019-19449 HIGH 7.8 linux linux_kernel In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can lead to slab-out-of-bounds read access in f2fs_build_segment_manager in fs/f2fs/segment.c, related to init_min_max_mtime in fs/f2fs/segment.c (because the second argument to get_seg_entry 2.1% —
CVE-2017-0582 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the HTC OEM fastboot command could enable a local malicious application to execute arbitrary code within the context of the sensor hub. This issue is rated as Moderate because it first requires exploitation of separat 2.1% —
CVE-2022-30665 HIGH 7.8 adobe indesign Adobe InDesign versions 17.2.1 (and earlier) and 16.4.1 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in 2.1% —