IT
57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.411 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-12270 HIGH 7.4 opentext brava\! OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group 1.5%
CVE-2018-8121 MED 4.7 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 10 Servers, Windows 10. This CVE ID is unique from CVE-2018-8207. 1.5%
CVE-2016-8451 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p 1.5%
CVE-1999-0195 MED 5.0 linux linux_kernel Denial of service in RPC portmapper allows attackers to register or unregister RPC services or spoof RPC services using a spoofed source IP address such as 127.0.0.1. 1.5%
CVE-2026-63514 HIGH 8.8 microsoft sharepoint_server Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.5%
CVE-2026-21514 HIGH 7.8 microsoft 365_apps Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally. 1.5%
CVE-2025-27491 HIGH 7.1 microsoft windows_10_1507 Use after free in Windows Hyper-V allows an authorized attacker to execute code over a network. 1.5%
CVE-2021-38890 HIGH 7.5 ibm sterling_connect\ IBM Sterling Connect:Direct Web Services 1.0 and 6.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 209507. 1.5%
CVE-2016-8980 HIGH 8.1 ibm bigfix_inventory IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available me 1.5%
CVE-2022-41081 HIGH 8.1 microsoft windows_10 Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability 1.5%
CVE-2021-42320 HIGH 8.0 microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability 1.5%
CVE-2021-37595 CRIT 9.8 freerdp freerdp In FreeRDP before 2.4.0 on Windows, wf_cliprdr_server_file_contents_request in client/Windows/wf_cliprdr.c has missing input checks for a FILECONTENTS_RANGE File Contents Request PDU. 1.5%
CVE-2021-24098 MED 5.5 microsoft windows_10 Windows Console Driver Denial of Service Vulnerability 1.5%
CVE-2019-1872 MED 5.3 cisco telepresence_video_communication_server A vulnerability in Cisco TelePresence Video Communication Server (VCS) and Cisco Expressway Series software could allow an unauthenticated, remote attacker to cause an affected system to send arbitrary network requests. The vulnerability is due to improper res 1.5%
CVE-2019-1629 MED 5.3 cisco integrated_management_controller A vulnerability in the configuration import utility of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to have write access and upload arbitrary data to the filesystem. The vulnerability is due to a failure to delet 1.5%
CVE-2018-0437 HIGH 7.8 cisco umbrella_enterprise_roaming_client A vulnerability in the Cisco Umbrella Enterprise Roaming Client (ERC) could allow an authenticated, local attacker to elevate privileges to Administrator. To exploit the vulnerability, the attacker must authenticate with valid local user credentials. This vuln 1.5%
CVE-2016-8491 CRIT 9.1 fortinet fortiwlc The presence of a hardcoded account named 'core' in Fortinet FortiWLC allows attackers to gain unauthorized read/write access via a remote shell. 1.5%
CVE-2016-0181 MED 5.5 microsoft windows_10 Microsoft Windows 10 Gold and 1511 allows local users to bypass the Virtual Secure Mode Hypervisor Code Integrity (HVCI) protection mechanism and perform RWX markings of kernel-mode pages via a crafted application, aka "Hypervisor Code Integrity Security Featu 1.5%
CVE-2015-7759 LOW 3.7 f5 big-ip_access_policy_manager BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, Link Controller, and PEM 12.0.0 before HF1, when the TCP profile for a virtual server is configured with Congestion Metrics Cache enabled, allow remote attackers to cause a denial of service (Traffic Management Microk 1.5%
CVE-2014-1956 MED 5.0 fortinet fortiweb CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. 1.5%
CVE-2013-1277 MED 4.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently 1.5%
CVE-2013-1276 MED 4.9 microsoft windows_7 Race condition in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges, and consequently 1.5%
CVE-2021-24009 HIGH 7.2 fortinet fortiwan Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow an authenticated attacker to execute arbitrary commands on the underlying system's shell via specifically craf 1.5%
CVE-2020-0978 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.5%
CVE-2020-0973 MED 5.4 microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. This CVE ID is unique from CVE- 1.5%