57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.479 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2018-0828 | HIGH 7.8 | microsoft windows_10 Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability". | 1.0% | — |
| CVE-2016-9204 | MED 6.5 | cisco nexus_1000v_intercloud_firmware A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. K | 1.0% | — |
| CVE-2014-3291 | MED 5.7 | cisco wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a zero value in Cisco Discovery Protocol packet data that is not properly handled during SNMP polling, aka Bug ID | 1.0% | — |
| CVE-2013-3458 | HIGH 7.1 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliances (ASA) devices, when SMP is used, do not properly process X.509 certificates, which allows remote attackers to cause a denial of service (device crash) via a large volume of (1) SSL or (2) TLS traffic, aka Bug ID CSCuh19462. | 1.0% | — |
| CVE-2012-0339 | MED 5.0 | cisco ios Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID | 1.0% | — |
| CVE-2009-4040 | MED 4.3 | phpmyfaq phpmyfaq Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page. | 1.0% | — |
| CVE-2025-64672 | HIGH 8.8 | microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. | 1.0% | — |
| CVE-2024-49117 | HIGH 8.8 | microsoft windows_11_22h2 Windows Hyper-V Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2024-30063 | MED 6.7 | microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-38139 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-32531 | MED 5.9 | apache bookkeeper The Apache Bookkeeper Java Client (before 4.14.6 and also 4.15.0) does not close the connection to the bookkeeper server when TLS hostname verification fails. This leaves the bookkeeper client vulnerable to a man in the middle attack. The problem affects Book | 1.0% | — |
| CVE-2021-34786 | MED 6.5 | cisco broadworks_commpilot_application_software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. | 1.0% | — |
| CVE-2020-27126 | MED 6.1 | cisco webex_meetings A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) wit | 1.0% | — |
| CVE-2020-16885 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker | 1.0% | — |
| CVE-2020-3450 | MED 4.9 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative credentials to conduct SQL injection attacks on an affected system. The vulnerability is due to imp | 1.0% | — |
| CVE-2020-0957 | HIGH 7.8 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0956, CVE-2020-0958. | 1.0% | — |
| CVE-2020-0877 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0887. | 1.0% | — |
| CVE-2019-12635 | MED 4.3 | cisco content_security_management_appliance A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correc | 1.0% | — |
| CVE-2017-5037 | HIGH 7.8 | debian debian_linux An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer. | 1.0% | — |
| CVE-2017-2636 | HIGH 7.0 | debian debian_linux Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline. | 1.0% | — |
| CVE-2017-3799 | MED 5.4 | cisco webex_meeting_center A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1. | 1.0% | — |
| CVE-2025-64666 | HIGH 7.5 | microsoft exchange_server Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-47539 | CRIT 9.8 | fortinet fortimail An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. | 1.0% | — |
| CVE-2021-47241 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ethtool: strset: fix message length calculation Outer nest for ETHTOOL_A_STRSET_STRINGSETS is not accounted for. This may result in ETHTOOL_MSG_STRSET_GET producing a warning like: calc | 1.0% | — |
| CVE-2023-52434 | HIGH 8.1 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential OOBs in smb2_parse_contexts() Validate offsets and lengths before dereferencing create contexts in smb2_parse_contexts(). This fixes following oops when accessing | 1.0% | — |