57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-38505 | MED 6.5 | mozilla firefox Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applications that wish to prevent copied data fro | 1.1% | — |
| CVE-2020-27715 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP 15.1.0-15.1.0.5 and 14.1.0-14.1.3, crafted TLS request to the BIG-IP management interface via port 443 can cause high (~100%) CPU utilization by the httpd daemon. | 1.1% | — |
| CVE-2025-59254 | HIGH 7.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2021-26605 | HIGH 7.5 | unidocs ezpdfreader An improper input validation vulnerability in the service of ezPDFReader allows attacker to execute arbitrary command. This issue occurred when the ezPDF launcher received and executed crafted input values through JSON-RPC communication. | 1.0% | — |
| CVE-2021-34513 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-34512 | HIGH 7.8 | microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-34498 | HIGH 7.8 | microsoft windows_10 Windows GDI Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-29692 | MED 5.9 | ibm security_identity_manager IBM Security Identity Manager 7.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man i | 1.0% | — |
| CVE-2019-0727 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector or the Visual Studio Standard Collector allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, a | 1.0% | — |
| CVE-2017-7013 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. watchOS before 3.2.3 is | 1.0% | — |
| CVE-2017-7010 | HIGH 7.8 | apple icloud An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. iCloud before 6.2.2 on Windows is affected. iTunes before 12.6.2 on Windows is affected. tvOS before 10.2.2 is affected. The issue involves the | 1.0% | — |
| CVE-2024-22233 | HIGH 7.5 | vmware spring_framework In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the ap | 1.0% | — |
| CVE-2023-21695 | HIGH 7.5 | microsoft windows_10 Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2022-46763 | HIGH 8.8 | trueconf server A SQL injection issue in a database stored function in TrueConf Server 5.2.0.10225 (fixed in 5.2.6.10025) allows a low-privileged database user to execute arbitrary SQL commands as the database administrator, resulting in execution of arbitrary code. | 1.0% | — |
| CVE-2021-31361 | MED 5.3 | juniper junos An Improper Check for Unusual or Exceptional Conditions vulnerability combined with Improper Handling of Exceptional Conditions in Juniper Networks Junos OS on QFX Series and PTX Series allows an unauthenticated network based attacker to cause increased FPC CP | 1.0% | — |
| CVE-2020-1143 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then | 1.0% | — |
| CVE-2015-6263 | MED 6.3 | cisco ios The RADIUS client implementation in Cisco IOS 15.4(3)M2.2, when a shared RADIUS secret is configured, allows remote RADIUS servers to cause a denial of service (device reload) via malformed answers, aka Bug ID CSCuu59324. | 1.0% | — |
| CVE-2015-6306 | HIGH 7.2 | cisco anyconnect_secure_mobility_client Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation file, aka Bug ID CSCuv11947. | 1.0% | — |
| CVE-2025-48814 | HIGH 7.5 | microsoft windows_10_1607 Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an unauthorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2025-48799 | HIGH 7.8 | microsoft windows_10_1607 Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally. | 1.0% | — |
| CVE-2025-24992 | MED 5.5 | microsoft windows_10_1507 Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 1.0% | — |
| CVE-2023-1193 | MED 6.5 | linux linux_kernel A use-after-free flaw was found in setup_async_work in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. This issue could allow an attacker to crash the system by accessing freed work. | 1.0% | — |
| CVE-2021-43237 | HIGH 7.8 | microsoft windows_10 Windows Setup Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-24346 | HIGH 7.8 | f5 njs njs through 0.4.3, used in NGINX, has a use-after-free in njs_json_parse_iterator_call in njs_json.c. | 1.0% | — |
| CVE-2020-3281 | HIGH 8.8 | cisco digital_network_architecture_center A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text. The vulnerability is due to the storage of certain unencrypted credenti | 1.0% | — |