57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-35283 | MED 6.5 | ibm security_verify_information_queue IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request. | 1.1% | — |
| CVE-2020-1030 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly allows arbitrary writing to the file system. An attacker who successfully exploited this vulnerability could run arbitrary code with elevated system privileges. | 1.1% | — |
| CVE-2019-6640 | MED 5.3 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.1-11.5.8, SNMP exposes sensitive configuration objects over insecure transmission channels. This issue is exposed when a passphrase is inserted into various p | 1.1% | — |
| CVE-2017-7731 | HIGH 7.5 | fortinet fortiportal A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature. | 1.1% | — |
| CVE-2016-6451 | MED 6.1 | cisco prime_collaboration_provisioning Multiple vulnerabilities in the web framework code of the Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. More I | 1.1% | — |
| CVE-2016-1008 | HIGH 8.4 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privilege | 1.1% | — |
| CVE-2012-2856 | HIGH 7.5 | google chrome The PDF functionality in Google Chrome before 21.0.1180.57 on Mac OS X and Linux, and before 21.0.1180.60 on Windows and Chrome Frame, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger out-o | 1.1% | — |
| CVE-2024-43482 | MED 6.5 | microsoft outlook Microsoft Outlook for iOS Information Disclosure Vulnerability | 1.1% | — |
| CVE-2021-0295 | MED 6.1 | juniper junos A vulnerability in the Distance Vector Multicast Routing Protocol (DVMRP) of Juniper Networks Junos OS on the QFX10K Series switches allows an attacker to trigger a packet forwarding loop, leading to a partial Denial of Service (DoS). The issue is caused by DV | 1.1% | — |
| CVE-2020-3479 | MED 6.1 | cisco ios A vulnerability in the implementation of Multiprotocol Border Gateway Protocol (MP-BGP) for the Layer 2 VPN (L2VPN) Ethernet VPN (EVPN) address family in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a de | 1.1% | — |
| CVE-2018-10512 | HIGH 7.5 | trendmicro control_manager A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerable installations, which may lead to a denial of server (DoS). | 1.1% | — |
| CVE-2017-0193 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to gain elevated privileges on a target | 1.1% | — |
| CVE-2010-3034 | MED 5.0 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a differ | 1.1% | — |
| CVE-2010-0575 | MED 5.0 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) software, possibly 6.0.x or possibly 4.1 through 6.0.x, allows remote attackers to bypass ACLs in the controller CPU, and consequently send network traffic to unintended segments or devices, via unspecified vectors, a differ | 1.1% | — |
| CVE-2023-36024 | HIGH 7.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-31469 | HIGH 8.8 | apache streampipes A REST interface in Apache StreamPipes (versions 0.69.0 to 0.91.0) was not properly restricted to admin-only access. This allowed a non-admin user with valid login credentials to elevate privileges beyond the initially assigned roles. The issue is resolved by | 1.1% | — |
| CVE-2020-5862 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.1, 15.0.0-15.0.1.1, and 14.1.0-14.1.2.2, under certain conditions, TMM may crash or stop processing new traffic with the DPDK/ENA driver on AWS systems while sending traffic. This issue does not affect any other platforms, hardware or v | 1.1% | — |
| CVE-2019-1185 | HIGH 7.3 | microsoft windows_10 An elevation of privilege vulnerability exists due to a stack corruption in Windows Subsystem for Linux. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authenticate | 1.1% | — |
| CVE-2017-12630 | MED 5.4 | apache drill In Apache Drill 1.11.0 and earlier when submitting form from Query page users are able to pass arbitrary script or HTML which will take effect on Profile page afterwards. Example: after submitting special script that returns cookie information from Query page, | 1.1% | — |
| CVE-2026-26115 | HIGH 8.8 | microsoft sql_server_2016 Improper validation of specified type of input in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-47966 | CRIT 9.8 | microsoft power_automate_for_desktop Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | 1.1% | — |
| CVE-2025-24860 | MED 5.4 | apache cassandra Incorrect Authorization vulnerability in Apache Cassandra allowing users to access a datacenter or IP/CIDR groups they should not be able to when using CassandraNetworkAuthorizer or CassandraCIDRAuthorizer. Users with restricted data center access can update | 1.1% | — |
| CVE-2024-43604 | MED 5.7 | microsoft outlook Outlook for Android Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-21717 | HIGH 8.8 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2022-41066 | MED 4.4 | microsoft dynamics_365_business_central_2019 Microsoft Dynamics Business Central Information Disclosure Vulnerability | 1.1% | — |