IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-21326 HIGH 7.8 microsoft windows_server_2022_23h2 Internet Explorer Remote Code Execution Vulnerability 1.3%
CVE-2024-21328 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Sales Spoofing Vulnerability 1.3%
CVE-2023-0003 MED 6.5 fedoraproject fedora A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. 1.3%
CVE-2021-28660 HIGH 8.8 debian debian_linux rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (un 1.3%
CVE-2021-1588 HIGH 8.6 cisco nx-os A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improp 1.3%
CVE-2020-0617 MED 6.0 microsoft windows_10 A denial of service vulnerability exists when Microsoft Hyper-V Virtual PCI on a host server fails to properly validate input from a privileged user on a guest operating system, aka 'Hyper-V Denial of Service Vulnerability'. 1.3%
CVE-2026-62912 MED 6.5 microsoft exchange_server Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a network. 1.3%
CVE-2025-47957 HIGH 8.4 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 1.3%
CVE-2025-24996 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows NTLM allows an unauthorized attacker to perform spoofing over a network. 1.3%
CVE-2024-47554 MED 4.3 apache commons_io Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 befor 1.3%
CVE-2023-29411 CRIT 9.8 schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow changes to administrative credentials, leading to potential remote code execution without requiring prior authentication on the Java RMI interface. 1.3%
CVE-2020-7849 HIGH 8.0 uprism curix A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability is due to insufficient input(server domain) validation. An attacker could exploit this vulnerability through cr 1.3%
CVE-2017-0296 HIGH 7.8 microsoft windows_10 Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allow an attacker to elevate privilege when tdx.sys fails to check the lengt 1.3%
CVE-2011-4023 HIGH 7.8 cisco nexus_2148t_fex_switch Memory leak in libcmd in Cisco NX-OS 5.0 on Nexus switches allows remote authenticated users to cause a denial of service (memory consumption) via SNMP requests, aka Bug ID CSCtr65682. 1.3%
CVE-2024-49147 CRIT 9.3 microsoft update_catalog Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. 1.3%
CVE-2022-34917 HIGH 7.5 apache kafka A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException 1.3%
CVE-2021-36975 HIGH 7.8 microsoft windows_10 Win32k Elevation of Privilege Vulnerability 1.3%
CVE-2021-0227 HIGH 7.5 juniper junos An improper restriction of operations within the bounds of a memory buffer vulnerability in Juniper Networks Junos OS J-Web on SRX Series devices allows an attacker to cause Denial of Service (DoS) by sending certain crafted HTTP packets. Continued receipt and 1.3%
CVE-2020-35609 MED 5.5 microsoft azure_sphere A denial-of-service vulnerability exists in the asynchronous ioctl functionality of Microsoft Azure Sphere 20.05. A sequence of specially crafted ioctl calls can cause a denial of service. An attacker can write shellcode to trigger this vulnerability. 1.3%
CVE-2020-15780 MED 6.7 canonical ubuntu_linux An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30. 1.3%
CVE-2018-25018 HIGH 7.8 rarlab unrar UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext. 1.3%
CVE-2022-43718 MED 5.4 apache superset Upload data forms do not correctly render user input leading to possible XSS attack vectors that can be performed by authenticated users with database connection update permissions. This issue affects Apache Superset version 1.5.2 and prior versions and versio 1.3%
CVE-2020-4762 HIGH 8.8 ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2, and 6.1.0.0 could allow an authenticated user to create a privileged account due to improper access controls. IBM X-Force ID: 188896. 1.3%
CVE-2017-5076 MED 6.5 google chrome Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 59.0.3071.86 for Mac, Windows, and Linux, and 59.0.3071.92 for Android, allowed a remote attacker to perform domain spoofing via IDN homographs in a crafted domain name. 1.3%
CVE-2017-3795 MED 5.4 cisco webex_meetings_server A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct arbitrary password changes against any non-administrative user. More Information: CSCuz03345. Known Affected Releases: 2.6. Known Fixed Releases: 2.7.1.12. 1.3%