IT
57.479 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.479 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-3468 MED 5.4 cisco sd-wan_firmware A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface imp 1.0%
CVE-2017-5036 HIGH 7.8 debian debian_linux A use after free in PDFium in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to have an unspecified impact via a crafted PDF file. 1.0%
CVE-2026-58291 MED 6.1 microsoft edge_chromium Operation on a resource after expiration or release in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. 1.0%
CVE-2025-59502 HIGH 7.5 microsoft windows_10_1809 Uncontrolled resource consumption in Windows Remote Procedure Call allows an unauthorized attacker to deny service over a network. 1.0%
CVE-2025-4231 HIGH 7.2 paloaltonetworks pan-os A command injection vulnerability in Palo Alto Networks PAN-OS® enables an authenticated administrative user to perform actions as the root user. The attacker must have network access to the management web interface and successfully authenticate to exploit th 1.0%
CVE-2022-37964 HIGH 7.8 microsoft windows_7 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2020-17041 HIGH 7.8 microsoft windows_10 Windows Print Configuration Elevation of Privilege Vulnerability 1.0%
CVE-2020-17024 HIGH 7.8 microsoft windows_10 Windows Client Side Rendering Print Provider Elevation of Privilege Vulnerability 1.0%
CVE-2020-10757 HIGH 7.8 canonical ubuntu_linux A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. 1.0%
CVE-2020-3205 HIGH 8.8 cisco ios A vulnerability in the implementation of the inter-VM channel of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (Industrial ISRs) and Cisco 1000 Series Connected Grid Routers (CGR1000) could allow an unauthenticated, adjacent a 1.0%
CVE-2020-0779 MED 5.5 microsoft windows_10 An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0798, CVE-2020-0814, CVE-2020-0842, CVE-2020-084 1.0%
CVE-2019-1090 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory, aka 'Windows dnsrlvr.dll Elevation of Privilege Vulnerability'. 1.0%
CVE-2019-1067 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. 1.0%
CVE-2019-0999 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory, aka 'DirectX Elevation of Privilege Vulnerability'. 1.0%
CVE-2017-8581 HIGH 7.0 microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to 1.0%
CVE-2016-3196 MED 5.4 fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in Fortinet FortiAnalyzer 5.x before 5.0.12 and 5.2.x before 5.2.6 and FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.6 allows remote authenticated users to inject arbitrary web script or HTML via the filename of a 1.0%
CVE-2012-5427 MED 4.0 cisco ios Cisco IOS Unified Border Element (CUBE) in Cisco IOS before 15.3(2)T allows remote authenticated users to cause a denial of service (input queue wedge) via a crafted series of RTCP packets, aka Bug ID CSCuc42518. 1.0%
CVE-2013-0683 HIGH 7.1 cogentdatahub cascade_datahub The DataSim and DataPid demonstration clients in Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote servers to cause a denial of service (i 1.0%
CVE-2011-2837 HIGH 7.5 google chrome Google Chrome before 14.0.835.163 on Linux does not use the PIC and PIE compiler options for position-independent code, which has unspecified impact and attack vectors. 1.0%
CVE-2005-4826 MED 6.1 cisco ios Unspecified vulnerability in the VLAN Trunking Protocol (VTP) feature in Cisco IOS 12.1(22)EA3 on Catalyst 2950T switches allows remote attackers to cause a denial of service (device reboot) via a crafted Subset-Advert message packet, a different issue than CV 1.0%
CVE-2025-32722 MED 5.5 microsoft windows_10_1507 Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally. 1.0%
CVE-2024-30048 HIGH 7.6 microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability 1.0%
CVE-2024-30047 HIGH 7.6 microsoft dynamics_365_customer_insights Dynamics 365 Customer Insights Spoofing Vulnerability 1.0%
CVE-2022-22319 MED 5.4 ibm robotic_process_automation IBM Robotic Process Automation 21.0.1 could allow a register user on the system to physically delete a queue that could cause disruption for any scripts dependent on the queue. IBM X-Force ID: 218366. 1.0%
CVE-2020-36401 HIGH 7.8 mruby mruby mruby 2.1.2 has a double free in mrb_default_allocf (called from mrb_free and obj_free). 1.0%