IT
57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-3184 HIGH 7.2 cisco prime_collaboration_provisioning A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based manage 0.9%
CVE-2020-3766 HIGH 7.8 adobe genuine_integrity_service Adobe Genuine Integrity Service versions Version 6.4 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. 0.9%
CVE-2014-6447 HIGH 7.1 juniper junos Multiple vulnerabilities exist in Juniper Junos J-Web error handling that may lead to cross site scripting (XSS) issues or crash the J-Web service (DoS). This affects Juniper Junos OS 12.1X44 before 12.1X44-D45, 12.1X46 before 12.1X46-D30, 12.1X47 before 12.1X 0.9%
CVE-2019-1164 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, 0.9%
CVE-2018-16189 HIGH 7.8 micco unlha32.dll Untrusted search path vulnerability in Self-Extracting Archives created by UNLHA32.DLL prior to Ver 3.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. 0.9%
CVE-2013-1208 MED 5.8 cisco nx-os The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers to intercept or modify network traffic by leveraging certain L 0.9%
CVE-2002-0839 HIGH 7.2 apache http_server The shared memory scoreboard in the HTTP daemon for Apache 1.3.x before 1.3.27 allows any user running as the Apache UID to send a SIGUSR1 signal to any process as root, resulting in a denial of service (process kill) or possibly other behaviors that would not 0.9%
CVE-2026-62702 MED 6.8 microsoft windows_10_21h2 Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network. 0.9%
CVE-2024-26203 HIGH 7.3 microsoft azure_data_studio Azure Data Studio Elevation of Privilege Vulnerability 0.9%
CVE-2022-22452 HIGH 7.5 ibm security_verify_governance IBM Security Verify Identity Manager 10.0 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 224918. 0.9%
CVE-2020-3549 HIGH 8.1 cisco secure_firewall_management_center A vulnerability in the sftunnel functionality of Cisco Firepower Management Center (FMC) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to obtain the device registration hash. The vulnerability is due 0.9%
CVE-2017-3126 MED 6.1 fortinet fortianalyzer_firmware An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter. 0.9%
CVE-2011-2545 MED 4.3 cisco spa2102_phone_adapter_with_router Cross-site scripting (XSS) vulnerability in the SIP implementation on the Cisco SPA8000 and SPA8800 before 6.1.11, SPA2102 and SPA3102 before 5.2.13, and SPA 500 series IP phones before 7.4.9 allows remote attackers to inject arbitrary web script or HTML via t 0.9%
CVE-2026-80089 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-80073 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-78515 MED 6.5 microsoft 365_apps Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-78453 MED 6.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Microsoft Windows SCSI Class System File allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-72974 MED 6.5 microsoft 365_apps Buffer over-read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-72956 MED 6.5 microsoft 365_apps Untrusted pointer dereference in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-72938 MED 6.5 microsoft 365_apps Access of resource using incompatible type ('type confusion') in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2025-21387 HIGH 7.8 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.9%
CVE-2017-8562 HIGH 7.0 microsoft windows_10 Microsoft Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability due to Windows improperly handling calls to Advanced Local Procedure Call (ALPC) 0.9%
CVE-2015-2877 LOW 3.3 linux linux_kernel Kernel Samepage Merging (KSM) in the Linux kernel 2.6.32 through 4.x does not prevent use of a write-timing side channel, which allows guest OS users to defeat the ASLR protection mechanism on other guest OS instances via a Cross-VM ASL INtrospection (CAIN) at 0.9%
CVE-2015-0623 MED 4.3 cisco web_security_appliance Cross-site scripting (XSS) vulnerability in the Administrator report page on Cisco Web Security Appliance (WSA) devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCus40627. 0.9%
CVE-2012-3047 MED 4.3 cisco scientific_atlanta_dpc2420 Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. 0.9%