IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2012-0333 MED 5.0 cisco small_business_ip_phone Cisco Small Business IP phones with SPA 500 series firmware 7.4.9 and earlier do not require authentication for Push XML requests, which allows remote attackers to make telephone calls via an XML document, aka Bug ID CSCts08768. 1.1%
CVE-2025-59185 MED 6.5 microsoft windows_10_1507 External control of file name or path in Windows Core Shell allows an unauthorized attacker to perform spoofing over a network. 1.1%
CVE-2023-42780 MED 6.5 apache airflow Apache Airflow, versions prior to 2.7.2, contains a security vulnerability that allows authenticated users of Airflow to list warnings for all DAGs, even if the user had no permission to see those DAGs. It would reveal the dag_ids and the stack-traces of impor 1.1%
CVE-2022-42971 CRIT 9.8 schneider-electric apc_easy_ups_online_monitoring_software A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could cause remote code execution when the attacker uploads a malicious JSP file. Affected Products: APC Easy UPS Online Monitoring Software (Windows 7, 10, 11 & Windows Serve 1.1%
CVE-2022-21932 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability 1.1%
CVE-2021-22097 MED 6.5 vmware spring_advanced_message_queuing_protocol In Spring AMQP versions 2.2.0 - 2.2.18 and 2.3.0 - 2.3.10, the Spring AMQP Message object, in its toString() method, will deserialize a body for a message with content type application/x-java-serialized-object. It is possible to construct a malicious java.util 1.1%
CVE-2021-29155 MED 5.5 debian debian_linux An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel 1.1%
CVE-2016-1156 MED 5.7 linecorp line LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline. 1.1%
CVE-2024-49041 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.1%
CVE-2022-44676 HIGH 8.1 microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.1%
CVE-2019-1316 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Microsoft Windows Setup when it does not properly handle privileges, aka 'Microsoft Windows Setup Elevation of Privilege Vulnerability'. 1.1%
CVE-2019-0998 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker 1.1%
CVE-2019-0983 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Storage Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges on the victim system. To exploit the vulnerability, an attacker 1.1%
CVE-2019-1706 HIGH 8.6 cisco adaptive_security_appliance_software A vulnerability in the software cryptography module of the Cisco Adaptive Security Virtual Appliance (ASAv) and Firepower 2100 Series running Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to cause an unexpecte 1.1%
CVE-2018-0422 HIGH 7.3 cisco webex_business_suite_31 A vulnerability in the folder permissions of Cisco Webex Meetings client for Windows could allow an authenticated, local attacker to modify locally stored files and execute code on a targeted device with the privilege level of the user. The vulnerability is du 1.1%
CVE-2015-5090 HIGH 7.2 adobe acrobat Adobe Reader and Acrobat 10.x before 10.1.15 and 11.x before 11.0.12, Acrobat and Acrobat Reader DC Classic before 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous before 2015.008.20082 on Windows and OS X allow attackers to bypass intended access 1.1%
CVE-2015-2572 MED 4.6 oracle hyperion_smart_view_for_office Unspecified vulnerability in the Oracle Hyperion Smart View for Office component in Oracle Hyperion 11.1.2.5.216 and earlier, when running on Windows, allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Core 1.1%
CVE-2012-5422 MED 6.8 cisco as5400_universal_gateway Unspecified vulnerability in Cisco IOS before 15.3(2)T on AS5400 devices allows remote authenticated users to cause a denial of service (spurious errors) via unknown vectors, aka Bug ID CSCub61009. 1.1%
CVE-2012-5036 MED 6.8 cisco ios Cisco IOS before 12.2(50)SY1 allows remote authenticated users to cause a denial of service (memory consumption) via a sequence of VTY management sessions (aka exec sessions), aka Bug ID CSCtn43662. 1.1%
CVE-2014-2103 MED 6.8 cisco intrusion_prevention_system Cisco Intrusion Prevention System (IPS) Software allows remote attackers to cause a denial of service (MainApp process outage) via malformed SNMP packets, aka Bug IDs CSCum52355 and CSCul49309. 1.1%
CVE-2026-50429 HIGH 8.2 microsoft windows_10_1607 Out-of-bounds read in Windows Kernel allows an unauthorized attacker to disclose information over a network. 1.1%
CVE-2021-1470 MED 4.9 cisco catalyst_sd-wan_manager A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to improper input validation of SQL que 1.1%
CVE-2024-43566 HIGH 7.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.1%
CVE-2023-36007 HIGH 7.6 microsoft send_customer_voice_survey_from_dynamics_365 Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability 1.1%
CVE-2023-28350 MED 6.1 faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. Attacker-supplied input is not validated/sanitized before being rendered in both the Teacher and Student Console applications, enabling an attacker to execute JavaScript in these applications. 1.1%