58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-21992 | HIGH 7.8 | microsoft windows_10 Windows Mobile Device Management Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2022-21857 | HIGH 8.8 | microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-21221 | MED 5.9 | fasthttp_project fasthttp The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue i | 2.5% | — |
| CVE-2017-15712 | MED 6.5 | apache oozie Vulnerability allows a user of Apache Oozie 3.1.3-incubating to 4.3.0 and 5.0.0-beta1 to expose private files on the Oozie server process. The malicious user can construct a workflow XML file containing XML directives and configuration that reference sensitive | 2.5% | — |
| CVE-2021-40119 | CRIT 9.8 | cisco policy_suite A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installation | 2.5% | — |
| CVE-2018-3962 | HIGH 7.3 | foxitsoftware phantompdf A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user t | 2.5% | — |
| CVE-2022-22037 | HIGH 7.5 | microsoft windows_10 Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | 2.5% | — |
| CVE-2022-24543 | HIGH 7.8 | microsoft windows_upgrade_assistant Windows Upgrade Assistant Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2021-34450 | HIGH 8.5 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 2.5% | — |
| CVE-2024-38132 | HIGH 7.5 | microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability | 2.5% | — |
| CVE-2022-30208 | MED 6.5 | microsoft windows_10 Windows Security Account Manager (SAM) Denial of Service Vulnerability | 2.5% | — |
| CVE-2020-1066 | HIGH 7.8 | microsoft .net_framework An elevation of privilege vulnerability exists in .NET Framework which could allow an attacker to elevate their privilege level. To exploit the vulnerability, an attacker would first have to access the local machine, and then run a malicious program. The updat | 2.5% | — |
| CVE-2017-11783 | HIGH 7.0 | microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka "Windows Eleva | 2.5% | — |
| CVE-2015-8104 | CRIT 10.0 | canonical ubuntu_linux The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c. | 2.5% | — |
| CVE-2008-1998 | HIGH 8.5 | ibm db2 The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter. | 2.5% | — |
| CVE-2022-40145 | CRIT 9.8 | apache karaf This vulnerable is about a potential code injection when an attacker has control of the target LDAP server using in the JDBC JNDI URL. The function jaas.modules.src.main.java.porg.apache.karaf.jass.modules.jdbc.JDBCUtils#doCreateDatasource use InitialContext. | 2.5% | — |
| CVE-2018-0384 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the detection engine of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass a URL-based access control policy that is configured to block traffic for an affected system. The vulnerability exists because | 2.5% | — |
| CVE-2014-5209 | MED 5.3 | f5 big-ip_access_policy_manager An Information Disclosure vulnerability exists in NTP 4.2.7p25 private (mode 6/7) messages via a GET_RESTRICT control message, which could let a malicious user obtain sensitive information. | 2.5% | — |
| CVE-2024-20687 | HIGH 7.5 | microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability | 2.5% | — |
| CVE-2019-18814 | CRIT 9.8 | linux linux_kernel An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c. | 2.5% | — |
| CVE-2022-35837 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 2.5% | — |
| CVE-2018-14289 | MED 6.5 | foxitsoftware foxit_reader This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.1.5096. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious f | 2.5% | — |
| CVE-2025-62221 | HIGH 7.8 | microsoft windows_10_1809 Use after free in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally. | 2.5% | |
| CVE-2022-45143 | HIGH 7.5 | apache tomcat The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to su | 2.5% | — |
| CVE-2010-2243 | HIGH 7.5 | linux linux_kernel A vulnerability exists in kernel/time/clocksource.c in the Linux kernel before 2.6.34 where on non-GENERIC_TIME systems (GENERIC_TIME=n), accessing /sys/devices/system/clocksource/clocksource0/current_clocksource results in an OOPS. | 2.5% | — |