57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-15429 | MED 5.3 | cisco hyperflex_hx_data_platform A vulnerability in the web-based UI of Cisco HyperFlex HX Data Platform Software could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability is due to a lack of proper input and authorization of HTTP | 1.1% | — |
| CVE-2025-53727 | HIGH 8.8 | microsoft sql_server_2016 Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-29969 | HIGH 7.5 | microsoft windows_10_1507 Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2024-6912 | CRIT 9.8 | perkinelmer processplus Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0. | 1.1% | — |
| CVE-2022-3640 | MED 5.5 | debian debian_linux A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patc | 1.1% | — |
| CVE-2021-1530 | MED 5.4 | cisco broadworks_messaging_server A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to access sensitive information or cause a partial denial of service (DoS) condition on an affected system. This v | 1.1% | — |
| CVE-2009-3087 | MED 5.0 | ibm lotus_domino Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8. | 1.1% | — |
| CVE-2024-38187 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-38185 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2024-30086 | HIGH 7.8 | microsoft windows_10_1507 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-35308 | MED 6.5 | microsoft windows_10_1507 Windows MSHTML Platform Security Feature Bypass Vulnerability | 1.1% | — |
| CVE-2022-35845 | HIGH 7.8 | fortinet fortitester Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.0 all versions, 4.0.0 through 4.2.0, 2.3.0 through 3.9.1 may allow an authenticated attacker to execute arbitra | 1.1% | — |
| CVE-2020-17071 | MED 5.5 | microsoft windows_10 Windows Delivery Optimization Information Disclosure Vulnerability | 1.1% | — |
| CVE-2020-17069 | MED 5.5 | microsoft windows_10 Windows NDIS Information Disclosure Vulnerability | 1.1% | — |
| CVE-2016-1357 | MED 5.3 | cisco cisco_policy_suite The password-management administration component in Cisco Policy Suite (CPS) 7.0.1.3, 7.0.2, 7.0.2-att, 7.0.3-att, 7.0.4-att, and 7.5.0 allows remote attackers to bypass intended RBAC restrictions and read unspecified data via unknown vectors, aka Bug ID CSCut | 1.1% | — |
| CVE-2011-4019 | MED 5.4 | cisco ios Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CS | 1.1% | — |
| CVE-2023-30576 | MED 6.8 | apache guacamole Apache Guacamole 0.9.10 through 1.5.1 may continue to reference a freed RDP audio input buffer. Depending on timing, this may allow an attacker to execute arbitrary code with the privileges of the guacd process. | 1.1% | — |
| CVE-2023-21705 | HIGH 8.8 | microsoft sql_server Microsoft SQL Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-0261 | HIGH 7.5 | juniper junos A vulnerability in the HTTP/HTTPS service used by J-Web, Web Authentication, Dynamic-VPN (DVPN), Firewall Authentication Pass-Through with Web-Redirect, and Captive Portal allows an unauthenticated attacker to cause an extended Denial of Service (DoS) for thes | 1.1% | — |
| CVE-2020-1070 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. An | 1.1% | — |
| CVE-2018-0902 | HIGH 7.8 | microsoft windows_10 The Cryptography Next Generation (CNG) kernel-mode driver (cng.sys) in Windows 10 Gold, 1511, 1607, 1703, and 1709. Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to the way the kernel-mode driver valida | 1.1% | — |
| CVE-2018-0884 | HIGH 7.8 | microsoft windows_10 Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to how objects are handled in memory, aka "Windows Security Feature Bypass Vulne | 1.1% | — |
| CVE-2011-3293 | MED 6.8 | cisco secure_access_control_server Multiple cross-site request forgery (CSRF) vulnerabilities in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.2 allow remote attackers to hijack the authentication of administrators for requests that insert cross-site scripting (XSS) sequence | 1.1% | — |
| CVE-2026-62898 | HIGH 7.5 | microsoft .net Use after free in Microsoft QUIC allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2023-36710 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Foundation Core Remote Code Execution Vulnerability | 1.1% | — |