57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.551 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-3184 | HIGH 7.2 | cisco prime_collaboration_provisioning A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based manage | 0.9% | — |
| CVE-2020-3766 | HIGH 7.8 | adobe genuine_integrity_service Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | 0.9% | — |
| CVE-2014-6447 | HIGH 7.1 | juniper junos Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X | 0.9% | — |
| CVE-2019-1164 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, | 0.9% | — |
| CVE-2018-16189 | HIGH 7.8 | micco unlha32.dll Untrusted search path vulnerability in Self-Extracting Archives created by UNLHA32.DLL prior to Ver 3.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | 0.9% | — |
| CVE-2013-1208 | MED 5.8 | cisco nx-os The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers to intercept or modify network traffic by leveraging certain L | 0.9% | — |
| CVE-2002-0839 | HIGH 7.2 | apache http_server The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not | 0.9% | — |
| CVE-2026-62702 | MED 6.8 | microsoft windows_10_21h2 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. | 0.9% | — |
| CVE-2024-26203 | HIGH 7.3 | microsoft azure_data_studio Azure Data Studio Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-22452 | HIGH 7.5 | ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. | 0.9% | — |
| CVE-2020-3549 | HIGH 8.1 | cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due | 0.9% | — |
| CVE-2017-3126 | MED 6.1 | fortinet fortianalyzer_firmware An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter. | 0.9% | — |
| CVE-2011-2545 | MED 4.3 | cisco spa2102_phone_adapter_with_router Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via t | 0.9% | — |
| CVE-2026-80089 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-80073 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-78515 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-78453 | MED 6.5 | microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72974 | MED 6.5 | microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72956 | MED 6.5 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2026-72938 | MED 6.5 | microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. | 0.9% | — |
| CVE-2025-21387 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2017-8562 | HIGH 7.0 | microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows improperly handling calls to Advanced Local Procedure Call (ALPC) | 0.9% | — |
| CVE-2015-2877 | LOW 3.3 | linux linux_kernel Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) at | 0.9% | — |
| CVE-2015-0623 | MED 4.3 | cisco web_security_appliance Cross-site scripting (XSS) vulnerability in the Administrator report page on Cisco Web Security Appliance (WSA) devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus40627. | 0.9% | — |
| CVE-2012-3047 | MED 4.3 | cisco scientific_atlanta_dpc2420 Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0.9% | — |