IT
57.298 CVE tracked
779 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.298 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2016-8398 CRIT 9.8 linux linux_kernel Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705. 1.6%
CVE-2008-0322 HIGH 7.8 microsoft windows_xp The I2O Utility Filter driver (i2omgmt.sys) 5.1.2600.2180 for Microsoft Windows XP sets Everyone/Write permissions for the "\\.\I2OExc" device interface, which allows local users to gain privileges. NOTE: this issue can be leveraged to overwrite arbitrary mem 1.6%
CVE-2023-31038 HIGH 8.8 apache log4cxx SQL injection in Log4cxx when using the ODBC appender to send log messages to a database.  No fields sent to the database were properly escaped for SQL injection.  This has been the case since at least version 0.9.0(released 2003-08-06) Note that Log4cxx i 1.6%
CVE-2023-25691 CRIT 9.8 apache apache-airflow-providers-google Improper Input Validation vulnerability in the Apache Airflow Google Provider. This issue affects Apache Airflow Google Provider versions before 8.10.0. 1.6%
CVE-2019-14215 HIGH 7.5 foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.11. The application could crash when calling xfa.event.rest XFA JavaScript due to accessing a wild pointer. 1.6%
CVE-2019-14214 HIGH 7.5 foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to a JavaScript Denial of Service when deleting pages in a document that contains only one page by calling a "t.hidden = true" function. 1.6%
CVE-2019-14210 HIGH 7.5 foxitsoftware phantompdf An issue was discovered in Foxit PhantomPDF before 8.3.10. The application could be exposed to Memory Corruption due to the use of an invalid pointer copy, resulting from a destructed string object. 1.6%
CVE-2019-13067 CRIT 9.8 f5 njs njs through 0.3.3, used in NGINX, has a buffer over-read in nxt_utf8_decode in nxt/nxt_utf8.c. This issue occurs after the fix for CVE-2019-12207 is in place. 1.6%
CVE-2026-9155 HIGH 8.8 gnu sed OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input validation. 1.6%
CVE-2026-21536 CRIT 9.8 microsoft devices_pricing_program Microsoft Devices Pricing Program Remote Code Execution Vulnerability 1.6%
CVE-2025-21364 HIGH 7.8 microsoft 365_apps Microsoft Excel Security Feature Bypass Vulnerability 1.6%
CVE-2021-28315 HIGH 7.8 microsoft windows_10 Windows Media Video Decoder Remote Code Execution Vulnerability 1.6%
CVE-2020-3168 HIGH 7.5 cisco nx-os A vulnerability in the Secure Login Enhancements capability of Cisco Nexus 1000V Switch for VMware vSphere could allow an unauthenticated, remote attacker to cause an affected Nexus 1000V Virtual Supervisor Module (VSM) to become inaccessible to users through 1.6%
CVE-2020-1160 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Microsoft Windows Graphics Component improperly handles objects in memory, aka 'Microsoft Graphics Component Information Disclosure Vulnerability'. 1.6%
CVE-2014-1715 HIGH 7.5 google chrome Directory traversal vulnerability in Google Chrome before 33.0.1750.152 on OS X and Linux and before 33.0.1750.154 on Windows has unspecified impact and attack vectors. 1.6%
CVE-2014-0674 MED 6.8 cisco video_surveillance_operations_manager Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from 1.6%
CVE-2025-62213 HIGH 7.0 microsoft windows_10_1607 Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. 1.6%
CVE-2024-43469 HIGH 8.8 microsoft azure_cyclecloud Azure CycleCloud Remote Code Execution Vulnerability 1.6%
CVE-2024-38114 HIGH 8.8 microsoft windows_10_1507 Windows IP Routing Management Snapin Remote Code Execution Vulnerability 1.6%
CVE-2023-21761 HIGH 7.5 microsoft exchange_server Microsoft Exchange Server Information Disclosure Vulnerability 1.6%
CVE-2013-1225 HIGH 7.8 cisco unified_customer_voice_portal Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, relate 1.6%
CVE-2004-0186 HIGH 7.2 linux linux_kernel smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting a Samba share that contains a setuid root program, whose setuid attributes are not cleared when the share is mounted. 1.6%
CVE-2022-37866 HIGH 7.5 apache ivy When Apache Ivy downloads artifacts from a repository it stores them in the local file system based on a user-supplied "pattern" that may include placeholders for artifacts coordinates like the organisation, module or version. If said coordinates contain "../" 1.6%
CVE-2022-26183 HIGH 8.8 pnpm pnpm PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is 1.6%
CVE-2020-5408 MED 6.5 pivotal_software spring_security Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious 1.6%