IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2022-21992 HIGH 7.8 microsoft windows_10 Windows Mobile Device Management Remote Code Execution Vulnerability 2.5% —
CVE-2022-21857 HIGH 8.8 microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability 2.5% —
CVE-2022-21221 MED 5.9 fasthttp_project fasthttp The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue i 2.5% —
CVE-2017-15712 MED 6.5 apache oozie Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive 2.5% —
CVE-2021-40119 CRIT 9.8 cisco policy_suite A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installation 2.5% —
CVE-2018-3962 HIGH 7.3 foxitsoftware phantompdf A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user t 2.5% —
CVE-2022-22037 HIGH 7.5 microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability 2.5% —
CVE-2022-24543 HIGH 7.8 microsoft windows_upgrade_assistant Windows Upgrade Assistant Remote Code Execution Vulnerability 2.5% —
CVE-2021-34450 HIGH 8.5 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 2.5% —
CVE-2024-38132 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.5% —
CVE-2022-30208 MED 6.5 microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability 2.5% —
CVE-2020-1066 HIGH 7.8 microsoft .net_framework An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The updat 2.5% —
CVE-2017-11783 HIGH 7.0 microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka "Windows Eleva 2.5% —
CVE-2015-8104 CRIT 10.0 canonical ubuntu_linux The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c. 2.5% —
CVE-2008-1998 HIGH 8.5 ibm db2 The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter. 2.5% —
CVE-2022-40145 CRIT 9.8 apache karaf This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext. 2.5% —
CVE-2018-0384 MED 5.8 cisco secure_firewall_management_center A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system. The vulnerability exists because 2.5% —
CVE-2014-5209 MED 5.3 f5 big-ip_access_policy_manager An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information. 2.5% —
CVE-2024-20687 HIGH 7.5 microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability 2.5% —
CVE-2019-18814 CRIT 9.8 linux linux_kernel An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c. 2.5% —
CVE-2022-35837 MED 6.5 microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability 2.5% —
CVE-2018-14289 MED 6.5 foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f 2.5% —
CVE-2025-62221 HIGH 7.8 microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. 2.5%
CVE-2022-45143 HIGH 7.5 apache tomcat The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to su 2.5% —
CVE-2010-2243 HIGH 7.5 linux linux_kernel A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results in an OOPS. 2.5% —