57.469 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.469 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-53781 | HIGH 7.7 | microsoft dcadsv5-series_azure_vm_firmware Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2024-2362 | CRIT 9.1 | lollms lollms_web_ui A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this vulnerability to delete any file on the system | 1.1% | — |
| CVE-2023-34053 | MED 5.3 | vmware spring_framework In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the appl | 1.1% | — |
| CVE-2023-21686 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-16153 | CRIT 9.8 | fortinet fortisiem A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device database via the use of static credentials. | 1.1% | — |
| CVE-2019-15995 | MED 6.5 | cisco dna_spaces\ A vulnerability in the web UI of Cisco DNA Spaces: Connector could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit t | 1.1% | — |
| CVE-2019-0656 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2015-6419 | MED 6.8 | cisco firesight_system_software Cisco FireSIGHT Management Center with software 4.10.3, 5.2.0, 5.3.0, 5.3.1, and 5.4.0 allows remote authenticated users to read arbitrary files via a crafted GET request, aka Bug ID CSCur25410. | 1.1% | — |
| CVE-2026-69342 | HIGH 7.5 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2024-41890 | MED 5.3 | apache answer Missing Release of Resource after Effective Lifetime vulnerability in Apache Answer. This issue affects Apache Answer: through 1.3.5. User sends multiple password reset emails, each containing a valid link. Within the link's validity period, this could poten | 1.1% | — |
| CVE-2023-29055 | HIGH 7.5 | apache kylin In Apache Kylin version 2.0.0 to 4.0.3, there is a Server Config web interface that displays the content of file 'kylin.properties', that may contain serverside credentials. When the kylin service runs over HTTP (or other plain text protocol), it is possible f | 1.1% | — |
| CVE-2023-42504 | MED 5.8 | apache superset An authenticated malicious user could initiate multiple concurrent requests, each requesting multiple dashboard exports, leading to a possible denial of service. This issue affects Apache Superset: before 3.0.0 | 1.1% | — |
| CVE-2022-20692 | HIGH 7.7 | cisco ios_xe A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low-privileged, authenticated, remote attacker to cause a denial of service condition (DoS) on an affected device. This vulnerability is due to insufficient resource managem | 1.1% | — |
| CVE-2019-20822 | CRIT 9.8 | foxitsoftware 3d An issue was discovered in the 3D Plugin Beta for Foxit Reader and PhantomPDF before 9.7.0.29430. It has an out-of-bounds write via incorrect image data. | 1.1% | — |
| CVE-2018-0983 | HIGH 7.0 | microsoft windows_10 Windows Storage Services in Windows 10 versions 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows Storage Services Elevation | 1.1% | — |
| CVE-2017-8694 | HIGH 7.0 | microsoft windows_10 The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privile | 1.1% | — |
| CVE-2017-8689 | HIGH 7.0 | microsoft windows_10 The Microsoft Windows Kernel Mode Driver on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privile | 1.1% | — |
| CVE-2016-2079 | MED 5.9 | vmware nsx_edge VMware NSX Edge 6.1 before 6.1.7 and 6.2 before 6.2.3 and vCNS Edge 5.5 before 5.5.4.3, when the SSL-VPN feature is configured, allow remote attackers to obtain sensitive information via unspecified vectors. | 1.1% | — |
| CVE-2002-2037 | MED 5.0 | cisco bams The Cisco Media Gateway Controller (MGC) in (1) SC2200 7.4 and earlier, (2) VSC3000 9.1 and earlier, (3) PGW 2200 9.1 and earlier, (4) Billing and Management Server (BAMS) and (5) Voice Services Provisioning Tool (VSPT) runs on default installations of Solaris | 1.1% | — |
| CVE-2025-21177 | HIGH 8.7 | microsoft dynamics_365_sales Server-side request forgery (ssrf) in Microsoft Dynamics 365 Sales allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2023-29337 | HIGH 7.1 | microsoft nuget NuGet Client Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-25621 | MED 6.5 | apache sling_i18n Privilege Escalation vulnerability in Apache Software Foundation Apache Sling. Any content author is able to create i18n dictionaries in the repository in a location the author has write access to. As these translations are used across the whole product, it al | 1.1% | — |
| CVE-2023-21808 | HIGH 7.8 | microsoft .net .NET and Visual Studio Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-42264 | MED 5.5 | adobe premiere_pro Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t | 1.1% | — |
| CVE-2021-42263 | MED 5.5 | adobe premiere_pro Adobe Premiere Pro 15.4.1 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of t | 1.1% | — |