IT
57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.298 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-26224 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.6%
CVE-2024-26223 HIGH 7.2 microsoft windows_server_2016 Windows DNS Server Remote Code Execution Vulnerability 1.6%
CVE-2021-31184 MED 5.5 microsoft windows_10 Microsoft Windows Infrared Data Association (IrDA) Information Disclosure Vulnerability 1.6%
CVE-2019-4614 MED 6.5 ibm mq IBM MQ and IBM MQ Appliance 8.0 and 9.0 LTS client connecting to a Queue Manager could cause a SIGSEGV denial of service caused by converting an invalid message. IBM X-Force ID: 168639. 1.6%
CVE-2019-1375 MED 5.4 microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. 1.6%
CVE-2019-12632 HIGH 7.5 cisco finesse A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on an affected system. The vulnerability exists because the affected system does not properly val 1.6%
CVE-2019-0876 MED 5.5 microsoft open_enclave_software_development_kit An information disclosure vulnerability exists when affected Open Enclave SDK versions improperly handle objects in memory, aka 'Open Enclave SDK Information Disclosure Vulnerability'. 1.6%
CVE-2016-7391 HIGH 7.8 nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x100010b where a missing array bounds ch 1.6%
CVE-2024-21302 MED 6.7 microsoft windows_10_1507 Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to 1.6%
CVE-2023-35384 MED 5.4 microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability 1.6%
CVE-2015-0762 MED 4.3 cisco unified_meetingplace Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified MeetingPlace 8.6(1.2) and 8.6(1.9) for Microsoft Outlook allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCuu51400. 1.6%
CVE-2015-0752 MED 4.3 cisco telepresence_video_communication_server Cross-site scripting (XSS) vulnerability in Cisco TelePresence Video Communication Server (VCS) X8.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCut27635. 1.6%
CVE-2015-0733 MED 4.3 cisco headend_digital_broadband_delivery_system CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Release allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks or cross-site scripting (XSS) att 1.6%
CVE-2023-24936 HIGH 7.5 microsoft .net .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability 1.6%
CVE-2022-23256 HIGH 8.1 microsoft azure_data_explorer Azure Data Explorer Spoofing Vulnerability 1.6%
CVE-2021-22056 HIGH 7.5 vmware identity_manager VMware Workspace ONE Access 21.08, 20.10.0.1, and 20.10 and Identity Manager 3.3.5, 3.3.4, and 3.3.3 contain an SSRF vulnerability. A malicious actor with network access may be able to make HTTP requests to arbitrary origins and read the full response. 1.6%
CVE-2014-3366 MED 6.5 cisco unified_communications_manager SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted response, aka Bug ID CSCup88089. 1.6%
CVE-2014-3275 MED 6.5 cisco identity_services_engine_software SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2(.1 patch 2) and earlier allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCul21337. 1.6%
CVE-2023-35321 MED 6.5 microsoft windows_server_2008 Windows Deployment Services Denial of Service Vulnerability 1.6%
CVE-2019-0047 HIGH 8.8 juniper junos A persistent Cross-Site Scripting (XSS) vulnerability in Junos OS J-Web interface may allow remote unauthenticated attackers to perform administrative actions on the Junos device. Successful exploitation requires a Junos administrator to first perform certain 1.6%
CVE-2017-3836 MED 4.3 cisco unified_communications_manager A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12 1.6%
CVE-2016-10086 HIGH 8.1 ca service_desk_management RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request. 1.6%
CVE-2015-6126 HIGH 7.2 microsoft windows_10 Race condition in the Pragmatic General Multicast (PGM) protocol implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 1.6%
CVE-2013-0268 MED 6.2 linux linux_kernel The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c. 1.6%
CVE-2012-4621 HIGH 7.8 cisco ios The Device Sensor feature in Cisco IOS 15.0 through 15.2 allows remote attackers to cause a denial of service (device reload) via a DHCP packet, aka Bug ID CSCty96049. 1.6%