IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2021-31973 HIGH 7.8 microsoft windows_10 Windows GPSVC Elevation of Privilege Vulnerability 0.5%
CVE-2021-31953 HIGH 7.8 microsoft windows_10 Windows Filter Manager Elevation of Privilege Vulnerability 0.5%
CVE-2021-31190 HIGH 7.8 microsoft windows_10 Windows Container Isolation FS Filter Driver Elevation of Privilege Vulnerability 0.5%
CVE-2021-28436 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5%
CVE-2021-28351 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5%
CVE-2021-28347 HIGH 7.8 microsoft windows_10 Windows Speech Runtime Elevation of Privilege Vulnerability 0.5%
CVE-2021-28320 HIGH 7.8 microsoft windows_10 Windows Resource Manager PSM Service Extension Elevation of Privilege Vulnerability 0.5%
CVE-2021-1137 HIGH 7.8 cisco catalyst_sd-wan_manager Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or allow an authenticated, local attacker to gain escalated privileges on an affected system. For more information about these v 0.5%
CVE-2020-3963 MED 5.5 vmware cloud_foundation VMware ESXi (7.0 before ESXi_7.0.0-1.20.16321839, 6.7 before ESXi670-202006401-SG and 6.5 before ESXi650-202005401-SG), Workstation (15.x before 15.5.2), and Fusion (11.x before 11.5.2) contain a use-after-free vulnerability in PVNVRAM. A malicious actor with 0.5%
CVE-2020-29012 MED 5.6 fortinet fortisandbox An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information about other users configured on the device, should the attacker be able to obtain 0.5%
CVE-2019-1632 MED 4.6 cisco integrated_management_controller A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The v 0.5%
CVE-2013-1130 MED 6.8 cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client on Mac OS X uses weak permissions for a library directory, which allows local users to gain privileges via a crafted library file, aka Bug ID CSCue33619. 0.5%
CVE-2005-2553 LOW 2.1 linux linux_kernel The find_target function in ptrace32.c in the Linux kernel 2.4.x before 2.4.29 does not properly handle a NULL return value from another function, which allows local users to cause a denial of service (kernel crash/oops) by running a 32-bit ltrace program with 0.5%
CVE-2026-55971 CRIT 9.8 apache thrift Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue. 0.6%
CVE-2026-44277 CRIT 9.8 fortinet fortiauthenticator A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, FortiAuthenticator 6.5.0 through 6.5.6 may allow attacker to execute unauthorized code or commands via crafted reque 0.6%
CVE-2026-32177 HIGH 7.3 microsoft .net Heap-based buffer overflow in .NET allows an unauthorized attacker to elevate privileges locally. 0.6%
CVE-2026-3087 HIGH 7.5 python python If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then the archive will be extracted outside the target directory which is different than other operating systems. Only Windows is affected by this v 0.6%
CVE-2026-26139 HIGH 8.6 microsoft purview Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-23663 HIGH 7.5 microsoft global_secure_access Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network. 0.6%
CVE-2026-0386 HIGH 7.5 microsoft windows_server_2008 Improper access control in Windows Deployment Services allows an unauthorized attacker to execute code over an adjacent network. 0.6%
CVE-2025-47849 HIGH 8.8 apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can get the API key and secret key of user-accounts of Admin role type in the same domain. This operation 0.6%
CVE-2025-47713 HIGH 8.8 apache cloudstack A privilege escalation vulnerability exists in Apache CloudStack versions 4.10.0.0 through 4.20.0.0 where a malicious Domain Admin user in the ROOT domain can reset the password of user-accounts of Admin role type. This operation is not appropriately restricte 0.6%
CVE-2024-46865 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: fou: fix initialization of grc The grc must be initialize first. There can be a condition where if fou is NULL, goto out will be executed and grc would be used uninitialized. 0.6%
CVE-2024-21339 MED 6.4 microsoft windows_10_1809 Windows USB Generic Parent Driver Remote Code Execution Vulnerability 0.6%
CVE-2024-20492 MED 6.0 cisco telepresence_video_communication_server A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker 0.6%