58.587 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.587 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2010-4587 | HIGH 9.3 | opera opera_browser Opera before 11.00 on Windows does not properly implement the Insecure Third Party Module warning message, which might make it easier for user-assisted remote attackers to have an unspecified impact via a crafted module. | 2.3% | — |
| CVE-2021-42316 | HIGH 8.8 | microsoft dynamics_365 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2004-2536 | HIGH 7.5 | linux linux_kernel The exit_thread function (process.c) in Linux kernel 2.6 through 2.6.5 does not invalidate the per-TSS io_bitmap pointers if a process obtains IO access permissions from the ioperm function but does not drop those permissions when it exits, which allows other | 2.3% | — |
| CVE-2023-35621 | HIGH 7.5 | microsoft dynamics_365 Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability | 2.3% | — |
| CVE-2019-0663 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory.To exploit this vulnerability, an authenticated attacker could run a specially crafted application, aka 'Windows Kernel Information Disclosure Vulne | 2.3% | — |
| CVE-2005-2940 | HIGH 7.2 | microsoft antispyware Unquoted Windows search path vulnerability in Microsoft Antispyware 1.0.509 (Beta 1) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, involving the programs (1) GIANTAntiSpywareMain.exe, (2) gcASNotice.exe, (3) gc | 2.3% | — |
| CVE-2018-0204 | HIGH 7.5 | cisco prime_collaboration_provisioning A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacke | 2.3% | — |
| CVE-2015-0586 | HIGH 7.8 | cisco ios The Network-Based Application Recognition (NBAR) protocol implementation in Cisco IOS 15.3(100)M and earlier on Cisco 2900 Integrated Services Router (aka Cisco Internet Router) devices allows remote attackers to cause a denial of service (NBAR process hang) v | 2.3% | — |
| CVE-2006-3288 | MED 5.0 | cisco wireless_control_system Unspecified vulnerability in the TFTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51), when configured to use a directory path name that contains a space character, allows remote authenticated users to read and overwrite arbi | 2.3% | — |
| CVE-2022-26907 | MED 5.3 | microsoft azure_sdk_for_.net Azure SDK for .NET Information Disclosure Vulnerability | 2.3% | — |
| CVE-2021-40456 | MED 5.3 | microsoft windows_server Windows AD FS Security Feature Bypass Vulnerability | 2.3% | — |
| CVE-2021-28451 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 2.3% | — |
| CVE-2018-0897 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 2.3% | — |
| CVE-2018-0894 | MED 4.7 | microsoft windows_10 The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information discl | 2.3% | — |
| CVE-2018-0832 | MED 4.7 | microsoft windows_10 The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an information disclosure vulnerability due to how objects in memory are handled, aka | 2.3% | — |
| CVE-2017-8465 | HIGH 7.8 | microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to run processes in an elevated context when the Windows kernel improperly handles objects in memory, aka "Win32k | 2.3% | — |
| CVE-2016-8399 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the kernel networking subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privilege | 2.3% | — |
| CVE-2015-4303 | MED 6.5 | cisco telepresence_video_communication_server_software Cisco TelePresence Video Communication Server (VCS) X8.5.2 allows remote authenticated users to execute arbitrary commands in the context of the nobody user account via an unspecified web-page parameter, aka Bug ID CSCuv12333. | 2.3% | — |
| CVE-2011-0165 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.3% | — |
| CVE-2011-0139 | HIGH 7.6 | apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability | 2.3% | — |
| CVE-2025-59516 | HIGH 7.8 | microsoft windows_10_1809 Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | 2.3% | — |
| CVE-2016-0190 | MED 5.5 | microsoft windows_8.1 Volume Manager Driver in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT 8.1 does not properly check whether RemoteFX RDP USB disk accesses originate from the user who mounted a disk, which allows local users to read arbitrary files on t | 2.3% | — |
| CVE-2014-0617 | HIGH 7.1 | juniper junos Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet. | 2.3% | — |
| CVE-2008-4816 | MED 4.3 | adobe acrobat Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors. | 2.3% | — |
| CVE-2005-2025 | MED 5.0 | cisco vpn_3000_concentrator Cisco VPN 3000 Concentrator before 4.1.7.F allows remote attackers to determine valid groupnames by sending an IKE Aggressive Mode packet with the groupname in the ID field, which generates a response if the groupname is valid, but does not generate a response | 2.3% | — |