IT
56.832 CVE tracked
777 Exploited now
183 Used by ransomware
Last sync

CVE Tracker

56.832 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sorted ascending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2000-0162 MED 5.1 microsoft ie The Microsoft virtual machine (VM) in Internet Explorer 4.x and 5.x allows a remote attacker to read files via a malicious Java applet that escapes the Java sandbox, aka the "VM File Reading" vulnerability. 7.6%
CVE-2000-0156 MED 5.1 microsoft internet_explorer Internet Explorer 4.x and 5.x allows remote web servers to access files on the client that are outside of its security domain, aka the "Image Source Redirect" vulnerability. 12.8%
CVE-1999-1578 MED 5.1 microsoft internet_explorer Buffer overflow in Registration Wizard ActiveX control (regwizc.dll, InvokeRegWizard) 3.0.0.0 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands. 19.4%
CVE-1999-1577 MED 5.1 microsoft internet_explorer Buffer overflow in HHOpen ActiveX control (hhopen.ocx) 1.0.0.1 for Internet Explorer 4.01 and 5 allows remote attackers to execute arbitrary commands via long arguments to the OpenHelp method. 19.5%
CVE-1999-1575 MED 5.1 microsoft internet_explorer The Kodak/Wang (1) Image Edit (imgedit.ocx), (2) Image Annotation (imgedit.ocx), (3) Image Scan (imgscan.ocx), (4) Thumbnail Image (imgthumb.ocx), (5) Image Admin (imgadmin.ocx), (6) HHOpen (hhopen.ocx), (7) Registration Wizard (regwizc.dll), and (8) IE Active 35.6%
CVE-1999-1128 MED 5.1 microsoft internet_explorer Internet Explorer 3.01 on Windows 95 allows remote malicious web sites to execute arbitrary commands via a .isp file, which is automatically downloaded and executed without prompting the user. 3.6%
CVE-1999-1093 MED 5.1 microsoft internet_explorer Buffer overflow in the Window.External function in the JScript Scripting Engine in Internet Explorer 4.01 SP1 and earlier allows remote attackers to execute arbitrary commands via a malicious web page. 12.6%
CVE-1999-0981 MED 5.1 microsoft internet_explorer Internet Explorer 5.01 and earlier allows a remote attacker to create a reference to a client window and use a server-side redirect to access local files via that window, aka "Server-side Page Reference Redirect." 13.1%
CVE-1999-0917 MED 5.1 microsoft internet_explorer The Preloader ActiveX control used by Internet Explorer allows remote attackers to read arbitrary files. 6.2%
CVE-1999-0750 MED 5.1 microsoft hotmail Hotmail allows Javascript to be executed via the HTML STYLE tag, allowing remote attackers to execute commands on the user's Hotmail account. 8.7%
CVE-1999-0668 MED 5.1 microsoft internet_explorer The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to execute arbitrary commands as demonstrated by Bubbleboy. 22.6%
CVE-1999-0061 MED 5.1 bsdi bsd_os File creation and deletion, and remote execution, in the BSD line printer daemon (lpd). 2.5%
CVE-2026-33921 MED 5.2 The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local user of the host instead of being restricted to administrators only. A local user without administrative privi 0.1%
CVE-2025-5781 MED 5.2 hitachi configuration_manager Information Exposure Vulnerability in Hitachi Ops Center API Configuration Manager, Hitachi Configuration Manager, Hitachi Device Manager allows Session Hijacking.This issue affects Hitachi Ops Center API Configuration Manager: from 10.0.0-00 before 11.0.5-00; 0.1%
CVE-2025-46707 MED 5.2 imaginationtech ddk Software installed and running inside a Guest VM may override Firmware's state and gain access to the GPU. 0.1%
CVE-2025-22221 MED 5.2 vmware aria_operations_for_logs VMware Aria Operation for Logs contains a stored cross-site scripting vulnerability. A malicious actor with admin privileges to VMware Aria Operations for Logs may be able to inject a malicious script that could be executed in a victim's browser when performin 0.4%
CVE-2024-21337 MED 5.2 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.4%
CVE-2021-36192 MED 5.2 fortinet fortimanager An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in FortiManager 7.0.1 and below, 6.4.6 and below, 6.2.x, 6.0.x, 5.6.0 may allow a FortiGate user to see scripts from other ADOMS. 0.2%
CVE-2021-31201 MED 5.2 microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability 2.6%
CVE-2021-31199 MED 5.2 microsoft windows_10_1507 Microsoft Enhanced Cryptographic Provider Elevation of Privilege Vulnerability 3.0%
CVE-2021-29827 MED 5.2 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and 0.3%
CVE-2021-21552 MED 5.2 microsoft windows_10 Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and 1.0%
CVE-2020-27223 MED 5.2 apache nifi In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due 78.0%
CVE-2019-12703 MED 5.2 cisco spa122_firmware A vulnerability in the web-based management interface of Cisco SPA122 ATA with Router Devices could allow an unauthenticated, adjacent attacker to conduct cross-site scripting attacks. The vulnerability is due to insufficient validation of user-supplied input 0.4%
CVE-2014-0102 MED 5.2 linux linux_kernel The keyring_detect_cycle_iterator function in security/keys/keyring.c in the Linux kernel through 3.13.6 does not properly determine whether keyrings are identical, which allows local users to cause a denial of service (OOPS) via crafted keyctl commands. 0.6%