56.569 CVE tracked
773 Exploited now
181 Used by ransomware
Last sync
CVE Tracker
56.569 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted ascending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-1999-1364 | LOW 2.1 | microsoft windows_nt Windows NT 4.0 allows local users to cause a denial of service (crash) via an illegal kernel mode address to the functions (1) GetThreadContext or (2) SetThreadContext. | 1.5% | — |
| CVE-1999-1363 | LOW 2.1 | microsoft windows_nt Windows NT 3.51 and 4.0 allow local users to cause a denial of service (crash) by running a program that creates a large number of locks on a file, which exhausts the NonPagedPool. | 1.5% | — |
| CVE-1999-1362 | LOW 2.1 | microsoft windows_nt Win32k.sys in Windows NT 4.0 before SP2 allows local users to cause a denial of service (crash) by calling certain WIN32K functions with incorrect parameters. | 1.4% | — |
| CVE-1999-1360 | LOW 2.1 | microsoft windows_nt Windows NT 4.0 allows local users to cause a denial of service via a user mode application that closes a handle that was opened in kernel mode, which causes a crash when the kernel attempts to close the handle. | 1.5% | — |
| CVE-1999-1294 | LOW 2.1 | microsoft windows_nt Office Shortcut Bar (OSB) in Windows 3.51 enables backup and restore permissions, which are inherited by programs such as File Manager that are started from the Shortcut Bar, which could allow local users to read folders for which they do not have permission. | 2.0% | — |
| CVE-1999-1285 | LOW 2.1 | linux linux_kernel Linux 2.1.132 and earlier allows local users to cause a denial of service (resource exhaustion) by reading a large buffer from a random device (e.g. /dev/urandom), which cannot be interrupted until the read has completed. | 0.3% | — |
| CVE-1999-1259 | LOW 2.1 | microsoft office Microsoft Office 98, Macintosh Edition, does not properly initialize the disk space used by Office 98 files and effectively inserts data from previously deleted files into the Office file, which could allow attackers to obtain sensitive information. | 2.5% | — |
| CVE-1999-1126 | LOW 2.1 | cisco resource_manager Cisco Resource Manager (CRM) 1.1 and earlier creates certain files with insecure permissions that allow local users to obtain sensitive configuration information including usernames, passwords, and SNMP community strings, from (1) swim_swd.log, (2) swim_debug. | 0.4% | — |
| CVE-1999-0782 | LOW 2.1 | freebsd freebsd KDE kppp allows local users to create a directory in an arbitrary location via the HOME environmental variable. | 0.3% | — |
| CVE-1999-0595 | LOW 2.1 | microsoft windows_2000 A Windows NT system does not clear the system page file during shutdown, which might allow sensitive information to be recorded. | 2.5% | — |
| CVE-1999-0585 | LOW 2.1 | microsoft windows_2000 A Windows NT administrator account has the default name of Administrator. | 2.5% | — |
| CVE-1999-0460 | LOW 2.1 | linux linux_kernel Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service. | 0.7% | — |
| CVE-1999-0451 | LOW 2.1 | linux linux_kernel Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port. | 0.7% | — |
| CVE-1999-0372 | LOW 2.1 | microsoft backoffice The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not deleted. | 4.2% | — |
| CVE-1999-0171 | LOW 2.1 | linux linux_kernel Denial of service in syslog by sending it a large number of superfluous messages. | 0.4% | — |
| CVE-2024-4811 | LOW 2.2 | octopus octopus_server In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | 0.2% | — |
| CVE-2024-27780 | LOW 2.2 | fortinet fortisiem Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site | 0.3% | — |
| CVE-2022-46647 | LOW 2.2 | intel unison_software Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | 0.2% | — |
| CVE-2022-46646 | LOW 2.2 | intel unison_software Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access. | 0.2% | — |
| CVE-2022-45469 | LOW 2.2 | intel unison_software Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access. | 0.2% | — |
| CVE-2022-33878 | LOW 2.2 | fortinet forticlient An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a local authenticated attacker to obtain the SSL-VPN password in cleartext via running a logstream for the Forti | 0.1% | — |
| CVE-2021-20406 | LOW 2.2 | ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 196184. | 0.5% | — |
| CVE-2026-44278 | LOW 2.3 | fortinet forticlient A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | 0.1% | — |
| CVE-2025-46777 | LOW 2.3 | fortinet fortiportal A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticated attacker with at least read-only admin permissions to view encrypted secrets vi | 0.2% | — |
| CVE-2024-54020 | LOW 2.3 | fortinet fortimanager A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feeds via crafted update requests. | 0.2% | — |