57.479 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-22026 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains a Server Side Request Forgery in an end point. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can perform a Server Side Request Forgery attack leadin | 1.1% | — |
| CVE-2020-1470 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Work Folders Service improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted a | 1.1% | — |
| CVE-2017-4920 | MED 5.9 | vmware nsx-v_edge The implementation of the OSPF protocol in VMware NSX-V Edge 6.2.x prior to 6.2.8 and NSX-V Edge 6.3.x prior to 6.3.3 doesn't correctly handle the link-state advertisement (LSA). A rogue LSA may exploit this issue resulting in continuous sending of LSAs betwee | 1.1% | — |
| CVE-2013-3406 | MED 6.8 | cisco service_portal The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCug65687. | 1.1% | — |
| CVE-2024-37981 | HIGH 8.0 | microsoft windows_10_1809 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2024-37977 | HIGH 8.0 | microsoft windows_11_21h2 Secure Boot Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2023-25601 | MED 4.3 | apache dolphinscheduler On version 3.0.0 through 3.1.1, Apache DolphinScheduler's python gateway suffered from improper authentication: an attacker could use a socket bytes attack without authentication. This issue has been fixed from version 3.1.2 onwards. For users who use version | 1.1% | — |
| CVE-2022-44670 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2017-5120 | MED 6.5 | debian debian_linux Inappropriate use of www mismatch redirects in browser navigation in Google Chrome prior to 61.0.3163.79 for Mac, Windows, and Linux, and 61.0.3163.81 for Android, allowed a remote attacker to potentially downgrade HTTPS requests to HTTP via a crafted HTML pag | 1.1% | — |
| CVE-2013-6693 | MED 5.4 | cisco 7600_router The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345. | 1.1% | — |
| CVE-2026-65086 | MED 6.8 | nvidia openshell NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. | 1.1% | — |
| CVE-2026-54113 | HIGH 7.5 | microsoft windows_10_1607 Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network. | 1.1% | — |
| CVE-2025-59499 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2022-45048 | HIGH 8.4 | apache ranger Authenticated users with appropriate privileges can create policies having expressions that can exploit code execution vulnerability. This issue affects Apache Ranger: 2.3.0. Users are recommended to update to version 2.4.0. | 1.1% | — |
| CVE-2015-4324 | MED 6.1 | cisco nx-os Buffer overflow in Cisco NX-OS on Nexus 1000V devices for VMware vSphere 7.3(0)ZN(0.81), Nexus 3000 devices 7.3(0)ZN(0.81), Nexus 4000 devices 4.1(2)E1(1c), Nexus 7000 devices 7.2(0)N1(0.1), and Nexus 9000 devices 7.3(0)ZN(0.81) allows remote attackers to caus | 1.1% | — |
| CVE-2025-49701 | HIGH 8.8 | microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-27309 | HIGH 7.4 | apache kafka While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated wit | 1.1% | — |
| CVE-2023-21526 | HIGH 7.4 | microsoft windows_10_1507 Windows Netlogon Information Disclosure Vulnerability | 1.1% | — |
| CVE-2023-0004 | MED 6.5 | fedoraproject fedora A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity | 1.1% | — |
| CVE-2022-20726 | MED 5.5 | cisco cgr1000_compute_module Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 1.1% | — |
| CVE-2018-13102 | HIGH 7.8 | anydesk anydesk AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability. | 1.1% | — |
| CVE-2008-1471 | HIGH 7.2 | panda panda_antivirus_and_firewall The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial of service (system crash or kernel panic), overwrite memory, or execute arbitrary code via a crafted IOCTL request that triggers an out-of-b | 1.1% | — |
| CVE-2026-45648 | HIGH 8.8 | microsoft windows_server_2022 Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-49069 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2024-37325 | HIGH 8.1 | microsoft azure_data_science_virtual_machine Azure Science Virtual Machine (DSVM) Elevation of Privilege Vulnerability | 1.1% | — |