57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-27075 | MED 6.8 | microsoft azure_container_instances Azure Virtual Machine Information Disclosure Vulnerability | 1.4% | — |
| CVE-2020-0672 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0668, CVE-2020-0669, CVE-2020-0670, CVE-2020-0671. | 1.4% | — |
| CVE-2020-0671 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0668, CVE-2020-0669, CVE-2020-0670, CVE-2020-0672. | 1.4% | — |
| CVE-2020-0670 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0668, CVE-2020-0669, CVE-2020-0671, CVE-2020-0672. | 1.4% | — |
| CVE-2013-5551 | MED 6.3 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN po | 1.4% | — |
| CVE-2019-1765 | HIGH 8.1 | cisco ip_conference_phone_8832_firmware A vulnerability in the web-based management interface of Session Initiation Protocol (SIP) Software for Cisco IP Phone 8800 Series could allow an authenticated, remote attacker to write arbitrary files to the filesystem. The vulnerability is due to insufficien | 1.4% | — |
| CVE-2019-11702 | MED 6.5 | mozilla firefox A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating sy | 1.4% | — |
| CVE-2018-18332 | HIGH 7.5 | trendmicro officescan A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations. | 1.4% | — |
| CVE-2018-18331 | HIGH 7.5 | trendmicro officescan A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations. | 1.4% | — |
| CVE-2014-1955 | MED 4.3 | fortinet fortiweb Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1.4% | — |
| CVE-2000-0311 | LOW 2.1 | microsoft windows_2000 The Windows 2000 domain controller allows a malicious user to modify Active Directory information by modifying an unprotected attribute, aka the "Mixed Object Access" vulnerability. | 1.4% | — |
| CVE-1999-0889 | HIGH 7.5 | cisco 675_router Cisco 675 routers running CBOS allow remote attackers to establish telnet sessions if an exec or superuser password has not been set. | 1.4% | — |
| CVE-2025-64157 | MED 6.7 | fortinet fortios A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via s | 1.4% | — |
| CVE-2024-31862 | MED 5.3 | apache zeppelin Improper Input Validation vulnerability in Apache Zeppelin when creating a new note from Zeppelin's UI.This issue affects Apache Zeppelin: from 0.10.1 before 0.11.0. Users are recommended to upgrade to version 0.11.0, which fixes the issue. | 1.4% | — |
| CVE-2022-44702 | HIGH 7.8 | microsoft terminal Windows Terminal Remote Code Execution Vulnerability | 1.4% | — |
| CVE-2022-27634 | MED 6.5 | f5 big-ip_access_policy_manager On 16.1.x versions prior to 16.1.2.2 and 15.1.x versions prior to 15.1.5.1, BIG-IP APM does not properly validate configurations, allowing an authenticated attacker with high privileges to manipulate the APM policy leading to privilege escalation/remote code e | 1.4% | — |
| CVE-2022-26488 | HIGH 7.0 | netapp active_iq_unified_manager In Python before 3.10.3 on Windows, local users can gain privileges because the search path is inadequately secured. The installer may allow a local attacker to add user-writable directories to the system search path. To exploit, an administrator must have ins | 1.4% | — |
| CVE-2021-31204 | HIGH 7.3 | fedoraproject fedora .NET and Visual Studio Elevation of Privilege Vulnerability | 1.4% | — |
| CVE-2021-1245 | MED 6.5 | cisco finesse Cisco Finesse and Cisco Unified CVP OpenSocial Gadget Editor Cross-Site Scripting Vulnerability A vulnerability in the web-based management interface of Cisco Finesse and Cisco Unified CVP could allow an unauthenticated, remote attacker to conduct a cross-s | 1.4% | — |
| CVE-2016-7271 | HIGH 7.8 | microsoft windows_10 The Secure Kernel Mode implementation in Microsoft Windows 10 Gold, 1511, and 1607 and Windows Server 2016 allows local users to bypass the virtual trust level (VTL) protection mechanism via a crafted application, aka "Secure Kernel Mode Elevation of Privilege | 1.4% | — |
| CVE-2010-2289 | MED 4.3 | juniper secure_access Open redirect vulnerability in dana/home/homepage.cgi in Juniper Networks IVE 6.5R1 (Build 14599) and 6.5R2 (Build 14951) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the Location parameter. | 1.4% | — |
| CVE-2008-2300 | MED 6.5 | citrix access_essentials Unspecified vulnerability in Citrix Presentation Server 4.5 and earlier, Citrix Access Essentials 2.0 and earlier, and Citrix Desktop Server 1.0 allows remote authenticated users to access unauthorized desktops via unknown attack vectors. | 1.4% | — |
| CVE-2022-42343 | MED 6.5 | adobe campaign Adobe Campaign version 7.3.1 (and earlier) and 8.3.9 (and earlier) are affected by a Server-Side Request Forgery (SSRF) vulnerability that could lead to arbitrary file system read. A low-privilege authenticated attacker can force the application to make arbitr | 1.4% | — |
| CVE-2020-0794 | MED 5.5 | microsoft windows_10 A denial of service vulnerability exists when Windows improperly handles objects in memory, aka 'Windows Denial of Service Vulnerability'. | 1.4% | — |
| CVE-2018-0020 | HIGH 7.5 | juniper junos Junos OS may be impacted by the receipt of a malformed BGP UPDATE which can lead to a routing process daemon (rpd) crash and restart. Receipt of a repeated malformed BGP UPDATEs can result in an extended denial of service condition for the device. This malform | 1.4% | — |