57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16943 | MED 6.5 | microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou | 1.1% | — |
| CVE-2019-16150 | MED 5.5 | fortinet forticlient Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensiti | 1.1% | — |
| CVE-2003-1569 | MED 5.0 | goahead goahead_webserver GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-200 | 1.1% | — |
| CVE-1999-0445 | MED 5.0 | cisco ios In Cisco routers under some versions of IOS 12.0 running NAT, some packets may not be filtered by input access list filters. | 1.1% | — |
| CVE-2026-20856 | HIGH 8.1 | microsoft windows_10_1607 Improper input validation in Windows Server Update Service allows an unauthorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-29737 | MED 4.7 | apache streampark In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to | 1.1% | — |
| CVE-2024-26220 | MED 5.0 | microsoft windows_10_1507 Windows Mobile Hotspot Information Disclosure Vulnerability | 1.1% | — |
| CVE-2024-21394 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Field Service Spoofing Vulnerability | 1.1% | — |
| CVE-2022-21969 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-21107 | CRIT 9.6 | debian debian_linux Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | 1.1% | — |
| CVE-2020-4636 | HIGH 7.2 | ibm resilient_security_orchestration_automation_and_response IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503. | 1.1% | — |
| CVE-2020-5924 | MED 5.3 | f5 big-ip_access_policy_manager In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set. | 1.1% | — |
| CVE-2020-12876 | HIGH 7.5 | veritas aptare Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments. | 1.1% | — |
| CVE-2020-0791 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898. | 1.1% | — |
| CVE-2019-6984 | MED 6.5 | foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter a Use-After-Free or Type Confusion and crash during handling of certain PDF files that embed specifically crafted 3D content, du | 1.1% | — |
| CVE-2019-6983 | MED 6.5 | foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Integer Overflow and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of a | 1.1% | — |
| CVE-2018-0788 | HIGH 7.0 | microsoft windows_7 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka | 1.1% | — |
| CVE-2014-3295 | MED 4.8 | cisco nx-os The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309. | 1.1% | — |
| CVE-2026-32093 | HIGH 7.0 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Function Discovery Service (fdwsd.dll) allows an authorized attacker to elevate privileges locally. | 1.1% | — |
| CVE-2025-55698 | HIGH 7.7 | microsoft windows_11_24h2 Null pointer dereference in Windows DirectX allows an authorized attacker to deny service over a network. | 1.1% | — |
| CVE-2023-34981 | HIGH 7.5 | apache tomcat A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (m | 1.1% | — |
| CVE-2023-26281 | MED 5.9 | ibm http_server IBM HTTP Server 8.5 used by IBM WebSphere Application Server could allow a remote user to cause a denial of service using a specially crafted URL. IBM X-Force ID: 248296. | 1.1% | — |
| CVE-2022-22197 | HIGH 7.5 | juniper junos An Operation on a Resource after Expiration or Release vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker with an established BGP session to cause a Denial of Se | 1.1% | — |
| CVE-2021-3046 | MED 6.8 | paloaltonetworks pan-os An improper authentication vulnerability exists in Palo Alto Networks PAN-OS software that enables a SAML authenticated attacker to impersonate any other user in the GlobalProtect Portal and GlobalProtect Gateway when they are configured to use SAML authentica | 1.1% | — |
| CVE-2018-8641 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows | 1.1% | — |