57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-3286 | MED 4.3 | netapp oncommand_insight Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multipl | 1.4% | — |
| CVE-2017-0099 | MED 5.4 | microsoft windows_10 Hyper-V in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and 2008 R2; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows guest OS users, running as virtual machines, to cause a de | 1.4% | — |
| CVE-2016-8492 | MED 5.9 | fortinet fortios The implementation of an ANSI X9.31 RNG in Fortinet FortiGate allows attackers to gain unauthorized read access to data handled by the device via IPSec/TLS decryption. | 1.4% | — |
| CVE-2013-3471 | MED 4.3 | cisco identity_services_engine_software The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515. | 1.4% | — |
| CVE-2007-1220 | MED 6.2 | microsoft xbox_360 The Hypervisor in Microsoft Xbox 360 kernel 4532 and 4548 does not properly verify the parameters passed to the syscall dispatcher, which allows attackers with physical access to bypass code-signing requirements and execute arbitrary code. | 1.4% | — |
| CVE-2005-3619 | MED 6.8 | vmware esx Cross-site scripting (XSS) vulnerability in the management interface for VMware ESX 2.5.x before 2.5.2 upgrade patch 2, 2.1.x before 2.1.2 upgrade patch 6, and 2.0.x before 2.0.1 upgrade patch 6 allows remote attackers to inject arbitrary web script or HTML vi | 1.4% | — |
| CVE-1999-0257 | MED 5.0 | linux linux_kernel Nestea variation of teardrop IP fragmentation denial of service. | 1.4% | — |
| CVE-2021-1246 | MED 6.5 | cisco finesse Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP OpenSocial Gadget Editor Unauthenticated Access Vulnerability A vulnerability in the web management interface of Cisco Finesse, Cisco Virtualized Voice Browser, and Cisco Unified CVP coul | 1.4% | — |
| CVE-2019-9966 | HIGH 7.8 | xnview xnview_classic XnView Classic 2.48 on Windows allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to xnview+0x38536c. | 1.4% | — |
| CVE-2019-1393 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1394, CVE-2019-1395, CVE-2019-1396, CVE-2019- | 1.4% | — |
| CVE-2026-41097 | MED 6.7 | microsoft windows_10_1809 Reliance on a component that is not updateable in Windows Secure Boot allows an authorized attacker to bypass a security feature locally. | 1.4% | — |
| CVE-2025-21314 | MED 6.5 | microsoft windows_10_1607 Windows SmartScreen Spoofing Vulnerability | 1.4% | — |
| CVE-2021-28546 | MED 6.5 | adobe acrobat Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a cer | 1.4% | — |
| CVE-2017-6169 | MED 6.8 | f5 big-ip_policy_enforcement_manager In versions 13.0.0, 12.0.0-12.1.3, or 11.6.0-11.6.2, an F5 BIG-IP virtual server using the URL categorization feature may cause the Traffic Management Microkernel (TMM) to produce a core file when it receives malformed URLs during categorization. | 1.4% | — |
| CVE-2017-12256 | MED 6.5 | cisco wide_area_application_services A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. The vulnerability is due to certain file | 1.4% | — |
| CVE-2014-2949 | MED 6.5 | f5 arx_data_manager SQL injection vulnerability in the web service in F5 ARX Data Manager 3.0.0 through 3.1.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 1.4% | — |
| CVE-2023-4136 | HIGH 7.4 | craftercms craftercms Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through | 1.4% | — |
| CVE-2022-26929 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2020-16920 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Application Compatibility Client Library improperly handles registry operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the | 1.4% | — |
| CVE-2017-12276 | HIGH 8.1 | cisco prime_collaboration_provisioning A vulnerability in the web framework code for the SQL database interface of the Cisco Prime Collaboration Provisioning application could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitra | 1.4% | — |
| CVE-2016-3349 | HIGH 7.8 | microsoft windows_10 The kernel-mode drivers in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." | 1.4% | — |
| CVE-2015-0622 | HIGH 7.1 | cisco wireless_lan_controller The Wireless Intrusion Detection (aka WIDS) functionality on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service (device outage) via crafted packets that are improperly handled during rendering of the Signature Even | 1.4% | — |
| CVE-2013-0882 | HIGH 7.5 | google chrome Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a large number of SVG parameters. | 1.4% | — |
| CVE-2024-8686 | HIGH 7.2 | paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. | 1.4% | — |
| CVE-2021-26871 | HIGH 7.8 | microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability | 1.4% | — |