IT
57.484 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.484 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2017-7109 MED 6.1 apple icloud An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" compone 1.0%
CVE-2026-50646 HIGH 7.8 microsoft .net Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally. 1.0%
CVE-2025-65037 CRIT 10.0 microsoft azure_container_apps Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-48817 HIGH 8.8 microsoft remote_desktop_client Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2025-29831 HIGH 7.5 microsoft windows_server_2008 Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network. 1.0%
CVE-2023-6240 MED 6.5 linux linux_kernel A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key. 1.0%
CVE-2023-46227 HIGH 7.5 apache inlong Deserialization of Untrusted Data Vulnerability in Apache Software Foundation Apache InLong. This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can use \t to bypass. Users are advised to upgrade to Apache InLong's 1.9.0 or cherry-pick [ 1.0%
CVE-2023-35394 MED 4.6 microsoft azure_hdinsight Azure HDInsight Jupyter Notebook Spoofing Vulnerability 1.0%
CVE-2022-38037 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0%
CVE-2022-21964 MED 5.5 microsoft windows_10 Remote Desktop Licensing Diagnoser Information Disclosure Vulnerability 1.0%
CVE-2021-44230 MED 6.5 portswigger burp_suite PortSwigger Burp Suite Enterprise Edition before 2021.11 on Windows has weak file permissions for the embedded H2 database, which might lead to privilege escalation. This issue can be exploited by an adversary who has already compromised a valid Windows accoun 1.0%
CVE-2020-3317 HIGH 7.5 cisco secure_firewall_threat_defense A vulnerability in the ssl_inspection component of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to crash Snort instances. The vulnerability is due to insufficient input validation in the ssl_inspection component 1.0%
CVE-2020-3519 HIGH 8.1 cisco data_center_network_manager A vulnerability in a specific REST API method of Cisco Data Center Network Manager (DCNM) Software could allow an authenticated, remote attacker to conduct a path traversal attack on an affected device. The vulnerability is due to insufficient validation of us 1.0%
CVE-2023-21778 HIGH 8.0 microsoft dynamics_365 Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability 1.0%
CVE-2022-0806 MED 6.5 google chrome Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who convinced a user to engage in screen sharing to potentially leak cross-origin data via a crafted HTML page. 1.0%
CVE-2020-4902 HIGH 8.8 ibm datacap_navigator IBM Datacap Taskmaster Capture (IBM Datacap Navigator 9.1.7) is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM 1.0%
CVE-2020-3307 MED 5.3 cisco secure_firewall_management_center A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to write arbitrary entries to the log file on an affected device. The vulnerability is due to insufficient input validation. An at 1.0%
CVE-2017-12227 MED 5.4 cisco emergency_responder A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that by 1.0%
CVE-2016-1470 HIGH 8.8 cisco small_business_220_series_smart_plus_switches Cross-site request forgery (CSRF) vulnerability in the web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1.1 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuz76230. 1.0%
CVE-2013-1406 HIGH 7.2 vmware esx The Virtual Machine Communication Interface (VMCI) implementation in vmci.sys in VMware Workstation 8.x before 8.0.5 and 9.x before 9.0.1 on Windows, VMware Fusion 4.1 before 4.1.4 and 5.0 before 5.0.2, VMware View 4.x before 4.6.2 and 5.x before 5.1.2 on Wind 1.0%
CVE-2011-4849 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session, as demo 1.0%
CVE-2011-4848 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 includes a submitted password within an HTTP response body, which allows remote attackers to obtain sensitive information by sniffing the network, as demonstrated by password handling in certai 1.0%
CVE-2011-4740 MED 4.3 parallels parallels_plesk_panel The Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 generates web pages containing external links in response to GET requests with query strings for smb/app/search-data/catalogId/marketplace and certain other files, which makes it easier for re 1.0%
CVE-2011-0217 MED 4.3 apple safari Apple Safari before 5.0.6 provides AutoFill information to scripts that execute before HTML form submission, which allows remote attackers to obtain Address Book information via a crafted form, as demonstrated by a form that includes non-visible fields. 1.0%
CVE-2023-36592 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 1.0%