57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-0766 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows AppX Deployment Server that allows file creation in arbitrary locations. To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege | 1.1% | — |
| CVE-2019-0696 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. | 1.1% | — |
| CVE-2018-8441 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists due to an integer overflow in Windows Subsystem for Linux, aka "Windows Subsystem for Linux Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. | 1.1% | — |
| CVE-2018-7636 | MED 6.1 | paloaltonetworks pan-os The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs. | 1.1% | — |
| CVE-2017-8466 | HIGH 7.8 | microsoft windows_10 Windows Cursor in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and Windows Server 2016 allows improper elevation of privilege, aka "Windows Cursor Elevation of Privilege Vulnerability". | 1.1% | — |
| CVE-2013-6694 | MED 4.3 | cisco ios The IPSec implementation in Cisco IOS allows remote attackers to cause a denial of service (MTU change and tunnel-session drop) via crafted ICMP packets, aka Bug ID CSCul29918. | 1.1% | — |
| CVE-2013-5555 | MED 4.3 | cisco unified_communications_manager Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349. | 1.1% | — |
| CVE-2012-5786 | MED 5.8 | apache cxf The wsdl_first_https sample code in distribution/src/main/release/samples/wsdl_first_https/src/main/ in Apache CXF before 2.7.0 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.50 | 1.1% | — |
| CVE-2010-1244 | MED 6.8 | apache activemq Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue | 1.1% | — |
| CVE-2024-49071 | MED 6.5 | microsoft defender_for_endpoint Improper authorization of an index that contains sensitive information from a Global Files search in Windows Defender allows an authorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2023-42790 | HIGH 8.1 | fortinet fortios A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0 through 6.4.14, FortiOS 6.2.0 through 6.2.15, FortiProxy 7.4.0, FortiProxy 7.2.0 through 7.2.6, FortiP | 1.1% | — |
| CVE-2021-42296 | HIGH 7.8 | microsoft 365_apps Microsoft Word Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-9116 | HIGH 7.8 | sublimetext sublime_text_3 DLL hijacking is possible in Sublime Text 3 version 3.1.1 build 3176 on 32-bit Windows platforms because a Trojan horse api-ms-win-core-fibers-l1-1-1.dll or api-ms-win-core-localization-l1-2-1.dll file may be loaded if a victim uses sublime_text.exe to open a | 1.1% | — |
| CVE-2018-1000117 | MED 6.7 | python python Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be explo | 1.1% | — |
| CVE-2013-5096 | MED 4.0 | juniper junos_space Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify the configuration by leveraging the read-only privilege, aka PR | 1.1% | — |
| CVE-2025-27749 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.1% | — |
| CVE-2025-27748 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.1% | — |
| CVE-2025-27745 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.1% | — |
| CVE-2022-31700 | HIGH 7.2 | vmware access VMware Workspace ONE Access and Identity Manager contain an authenticated remote code execution vulnerability. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.2. | 1.1% | — |
| CVE-2014-3342 | MED 4.0 | cisco cli The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383. | 1.1% | — |
| CVE-2013-3425 | MED 4.0 | cisco webex The Meeting Center component in Cisco WebEx 11 generates different error messages for invalid file-access attempts depending on whether a file exists, which allows remote authenticated users to enumerate files via a series of SPI calls, aka Bug ID CSCuc35965. | 1.1% | — |
| CVE-2024-50562 | MED 4.8 | fortinet fortios An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions may allow an attacker in possession of a cookie used to log in the SSL-VPN portal | 1.1% | — |
| CVE-2023-6753 | HIGH 8.8 | lfprojects mlflow Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. | 1.1% | — |
| CVE-2023-38434 | HIGH 7.5 | xhttp_project xhttp xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method. | 1.1% | — |
| CVE-2022-34302 | MED 6.7 | horizondatasys uefi_bootloader A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace | 1.1% | — |