57.490 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.490 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2015-6371 | MED 4.0 | cisco firepower_extensible_operating_system Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to read arbitrary files via crafted parameters to unspecified scripts, aka Bug ID CSCux10621. | 1.0% | — |
| CVE-2025-59284 | LOW 3.3 | microsoft windows_11_22h2 Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally. | 1.0% | — |
| CVE-2023-36598 | HIGH 7.8 | microsoft windows_10_1507 Microsoft WDAC ODBC Driver Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2023-36908 | MED 6.5 | microsoft windows_10 Windows Hyper-V Information Disclosure Vulnerability | 1.0% | — |
| CVE-2023-24935 | MED 6.1 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 1.0% | — |
| CVE-2022-21995 | HIGH 7.9 | microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2021-28954 | HIGH 7.8 | bit_project bit In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository. | 1.0% | — |
| CVE-2021-26899 | HIGH 7.8 | microsoft windows_10 Windows UPnP Device Host Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-0648 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows RSoP Service Application improperly handles memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a speci | 1.0% | — |
| CVE-2020-14356 | HIGH 7.8 | canonical ubuntu_linux A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system. | 1.0% | — |
| CVE-2019-5590 | MED 6.1 | fortinet fortiweb The URL part of the report message is not encoded in Fortinet FortiWeb 6.0.2 and below which may allow an attacker to execute unauthorized code or commands (Cross Site Scripting) via attack reports generated in HTML form. | 1.0% | — |
| CVE-2026-47301 | HIGH 8.8 | microsoft configuration_manager_2503 Improper access control in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2023-44794 | CRIT 9.8 | dromara sa-token An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload to the URL. | 1.0% | — |
| CVE-2023-20045 | MED 4.9 | cisco rv160_vpn_router_firmware A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulne | 1.0% | — |
| CVE-2022-47929 | MED 5.5 | debian debian_linux In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class | 1.0% | — |
| CVE-2019-19793 | HIGH 8.8 | cyxtera appgate_sdp In Cyxtera AppGate SDP Client 4.1.x through 4.3.x before 4.3.2 on Windows, a local or remote user from the same domain can gain privileges. | 1.0% | — |
| CVE-2024-36263 | HIGH 8.1 | apache submarine ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Submarine Server Core. This issue affects Apache Submarine Server Core: all versions. As this project is retired, we | 1.0% | — |
| CVE-2024-21385 | HIGH 8.3 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2023-25930 | MED 5.9 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.1, 11.1, and 11.5 is vulnerable to a denial of service. Under rare conditions, setting a special register may cause the Db2 server to terminate abnormally. IBM X-Force ID: 247862. | 1.0% | — |
| CVE-2022-20730 | MED 4.0 | cisco secure_firewall_threat_defense A vulnerability in the Security Intelligence feed feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the Security Intelligence DNS feed. This vulnerability is due to incorrect feed update processi | 1.0% | — |
| CVE-2021-20426 | CRIT 9.8 | ibm security_guardium IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313. | 1.0% | — |
| CVE-2020-17077 | HIGH 7.8 | microsoft windows_10 Windows Update Stack Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2020-1079 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code. An attacker could then install programs; view, change, or delete dat | 1.0% | — |
| CVE-2014-3631 | HIGH 7.2 | linux linux_kernel The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and syste | 1.0% | — |
| CVE-2009-4922 | MED 6.8 | cisco asa_5580 Unspecified vulnerability on Cisco Adaptive Security Appliances (ASA) 5580 series devices with software before 8.1(2) allows remote authenticated users to cause a denial of service (traceback) by establishing many IPsec L2L tunnels from remote peer IP addresse | 1.0% | — |