IT
57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2021-22026 HIGH 7.5 vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leadin 1.1%
CVE-2020-1470 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted a 1.1%
CVE-2017-4920 MED 5.9 vmware nsx-v_edge The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may exploit this issue resulting in continuous sending of LSAs betwee 1.1%
CVE-2013-3406 MED 6.8 cisco service_portal The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCug65687. 1.1%
CVE-2024-37981 HIGH 8.0 microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability 1.1%
CVE-2024-37977 HIGH 8.0 microsoft windows_11_21h2 Secure Boot Security Feature Bypass Vulnerability 1.1%
CVE-2023-25601 MED 4.3 apache dolphinscheduler On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version 1.1%
CVE-2022-44670 HIGH 8.1 microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2017-5120 MED 6.5 debian debian_linux Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML pag 1.1%
CVE-2013-6693 MED 5.4 cisco 7600_router The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345. 1.1%
CVE-2026-65086 MED 6.8 nvidia openshell NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. 1.1%
CVE-2026-54113 HIGH 7.5 microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. 1.1%
CVE-2025-59499 HIGH 8.8 microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. 1.1%
CVE-2022-45048 HIGH 8.4 apache ranger Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. 1.1%
CVE-2015-4324 MED 6.1 cisco nx-os Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to caus 1.1%
CVE-2025-49701 HIGH 8.8 microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. 1.1%
CVE-2024-27309 HIGH 7.4 apache kafka While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated wit 1.1%
CVE-2023-21526 HIGH 7.4 microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability 1.1%
CVE-2023-0004 MED 6.5 fedoraproject fedora A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity 1.1%
CVE-2022-20726 MED 5.5 cisco cgr1000_compute_module Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system 1.1%
CVE-2018-13102 HIGH 7.8 anydesk anydesk AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability. 1.1%
CVE-2008-1471 HIGH 7.2 panda panda_antivirus_and_firewall The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-b 1.1%
CVE-2026-45648 HIGH 8.8 microsoft windows_server_2022 Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. 1.1%
CVE-2024-49069 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 1.1%
CVE-2024-37325 HIGH 8.1 microsoft azure_data_science_virtual_machine Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability 1.1%