IT
58.559 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.559 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2018-8426 MED 5.4 microsoft sharepoint_enterprise_server_2013 A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft Office SharePoint XSS Vulnerability." This affects Microsoft SharePoi 2.3% —
CVE-2018-0440 HIGH 7.2 cisco data_center_network_manager A vulnerability in the web interface of Cisco Data Center Network Manager could allow an authenticated application administrator to execute commands on the underlying operating system with root-level privileges. The vulnerability is due to incomplete input val 2.3% —
CVE-2017-1000370 HIGH 7.8 linux linux_kernel The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed with 1GB of arguments or environmental strings then the stack occupies the address 0x80000000 and the PIE binary is mapped above 0x40000000 nul 2.3% —
CVE-2009-2862 MED 4.3 cisco ios The Object Groups for Access Control Lists (ACLs) feature in Cisco IOS 12.2XNB, 12.2XNC, 12.2XND, 12.4MD, 12.4T, 12.4XZ, and 12.4YA allows remote attackers to bypass intended access restrictions via crafted requests, aka Bug IDs CSCsx07114, CSCsu70214, CSCsw47 2.3% —
CVE-2015-8555 HIGH 8.6 citrix xenserver Xen 4.6.x, 4.5.x, 4.4.x, 4.3.x, and earlier do not initialize x86 FPU stack and XMM registers when XSAVE/XRSTOR are not used to manage guest extended register state, which allows local guest domains to obtain sensitive information from other domains via unspec 2.3% —
CVE-2018-0260 MED 5.3 cisco mate_live A vulnerability in the web interface of Cisco MATE Live could allow an unauthenticated, remote attacker to view and download the contents of certain web application virtual directories. The vulnerability is due to lack of proper input validation and authorizat 2.3% —
CVE-2014-8000 MED 5.0 cisco unified_communications_manager_im_and_presence_service Cisco Unified Communications Manager IM and Presence Service 9.1(1) produces different returned messages for URL requests depending on whether a username exists, which allows remote attackers to enumerate user accounts via a series of requests, aka Bug ID CSCu 2.3% —
CVE-2014-3279 MED 5.0 cisco unified_communications_domain_manager The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSC 2.3% —
CVE-2021-1433 HIGH 8.1 cisco ios_xe A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when the device processes traffic 2.3% —
CVE-2018-8498 MED 5.4 microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.3% —
CVE-2018-8488 MED 5.4 microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.3% —
CVE-2018-8480 MED 5.4 microsoft sharepoint_enterprise_server_2016 An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.3% —
CVE-2000-0089 LOW 2.1 microsoft windows_nt The rdisk utility in Microsoft Terminal Server Edition and Windows NT 4.0 stores registry hive information in a temporary file with permissions that allow local users to read it, aka the "RDISK Registry Enumeration File" vulnerability. 2.3% —
CVE-2026-43500 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handler in rxrpc_input_call_event() and the RESPONSE handler in rxrpc_verify_response() copy the skb to 2.3% —
CVE-2022-24483 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 2.3% —
CVE-2020-13417 CRIT 9.8 aviatrix controller An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters. 2.3% —
CVE-2019-9489 HIGH 7.5 trendmicro apex_one A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console. 2.3% —
CVE-2018-8568 MED 5.4 microsoft sharepoint_enterprise_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.3% —
CVE-2013-3899 HIGH 7.2 microsoft windows_server_2003 win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate addresses, which allows local users to gain privileges via a crafted application, aka "Win32k Memory Corruption Vulnerability." 2.3% —
CVE-2026-48576 HIGH 7.9 microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 2.3% —
CVE-2026-48573 HIGH 7.9 microsoft windows_10_1607 No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. 2.3% —
CVE-2022-23300 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 2.3% —
CVE-2022-23295 HIGH 7.8 microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability 2.3% —
CVE-2022-21927 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.3% —
CVE-2022-21926 HIGH 7.8 microsoft hevc_video_extensions HEVC Video Extensions Remote Code Execution Vulnerability 2.3% —