IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2017-8486 MED 4.7 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an information disclosure due to the way it handles objects in memory, ak 2.2% —
CVE-2016-8440 CRIT 9.8 linux linux_kernel Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747. 2.2% —
CVE-2018-8212 MED 5.3 microsoft windows_10 A security feature bypass vulnerability exists in Device Guard that could allow an attacker to inject malicious code into a Windows PowerShell session, aka "Device Guard Code Integrity Policy Security Feature Bypass Vulnerability." This affects Windows Server 2.2% —
CVE-2017-3153 MED 6.1 apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to Reflected XSS in the search functionality. 2.2% —
CVE-2017-3152 MED 6.1 apache atlas Apache Atlas versions 0.6.0-incubating and 0.7.0-incubating were found vulnerable to DOM XSS in the edit-tag functionality. 2.2% —
CVE-2022-24487 HIGH 8.8 microsoft windows_10 Windows Local Security Authority Subsystem Service (LSASS) Remote Code Execution Vulnerability 2.2% —
CVE-2020-10867 CRIT 9.8 avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to bypass intended access restrictions on tasks from an untrusted process, when Self Defense is enabled. 2.2% —
CVE-2019-6617 MED 6.5 f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, a user with the Resource Administrator role is able to overwrite sensitive low-level files (such as /etc/passwd) using SFTP to modify user permissions, without Advan 2.2% —
CVE-2016-1566 MED 5.4 apache guacamole Cross-site scripting (XSS) vulnerability in the file browser in Guacamole 0.9.8 and 0.9.9, when file transfer is enabled to a location shared by multiple users, allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename. N 2.2% —
CVE-2025-26647 HIGH 8.8 microsoft windows_server_2008 Improper input validation in Windows Kerberos allows an authorized attacker to elevate privileges over a network. 2.2% —
CVE-2024-26202 HIGH 7.2 microsoft windows_server_2012 DHCP Server Service Remote Code Execution Vulnerability 2.2% —
CVE-2024-26195 HIGH 7.2 microsoft windows_server_2008 DHCP Server Service Remote Code Execution Vulnerability 2.2% —
CVE-2022-38036 HIGH 7.5 microsoft windows_11 Internet Key Exchange (IKE) Protocol Denial of Service Vulnerability 2.2% —
CVE-2022-33645 HIGH 7.5 microsoft windows_10 Windows TCP/IP Driver Denial of Service Vulnerability 2.2% —
CVE-2020-1523 HIGH 8.9 microsoft sharepoint_server <p>A tampering vulnerability exists when Microsoft SharePoint Server fails to properly handle profile data. An attacker who successfully exploited this vulnerability could modify a targeted user's profile data.</p> <p>To exploit the vulnerability, an attacker 2.2% —
CVE-2002-0507 LOW 2.1 microsoft exchange_server An interaction between Microsoft Outlook Web Access (OWA) with RSA SecurID allows local users to bypass the SecurID authentication for a previous user via several submissions of an OWA Authentication request with the proper OWA password for the previous user, 2.2% —
CVE-2022-30206 HIGH 7.8 microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability 2.2% —
CVE-2019-15901 HIGH 8.8 doas_project doas An issue was discovered in slicer69 doas before 6.2 on certain platforms other than OpenBSD. A setusercontext(3) call with flags to change the UID, primary GID, and secondary GIDs was replaced (on certain platforms: Linux and possibly NetBSD) with a single set 2.2% —
CVE-2018-0007 CRIT 9.8 juniper junos An unauthenticated network-based attacker able to send a maliciously crafted LLDP packet to the local segment, through a local segment broadcast, may be able to cause a Junos device to enter an improper boundary check condition allowing a memory corruption to 2.2% —
CVE-2005-0176 MED 5.0 linux linux_kernel The shmctl function in Linux 2.6.9 and earlier allows local users to unlock the memory of other processes, which could cause sensitive memory to be swapped to disk, which could allow it to be read by other users once it has been released. 2.2% —
CVE-2024-43565 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.2% —
CVE-2024-43562 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.2% —
CVE-2024-43545 HIGH 7.5 microsoft windows_server_2008 Windows Online Certificate Status Protocol (OCSP) Server Denial of Service Vulnerability 2.2% —
CVE-2024-43544 HIGH 7.5 microsoft windows_server_2008 Microsoft Simple Certificate Enrollment Protocol Denial of Service Vulnerability 2.2% —
CVE-2022-23193 MED 5.5 adobe illustrator Adobe Illustrator versions 25.4.3 (and earlier) and 26.0.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Ex 2.2% —