IT
57.551 CVE tracked
782 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2020-16902 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists in the Windows Installer when the Windows Installer fails to properly sanitize input leading to an insecure library loading behavior.</p> <p>A locally authenticated attacker could run arbitrary code with elevat 0.9%
CVE-2020-1316 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, 0.9%
CVE-2020-1246 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1262, CVE-2020-1264, 0.9%
CVE-2014-3180 CRIT 9.1 google chrome_os In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code pa 0.9%
CVE-2019-17070 MED 6.1 lqd liquid_speech_balloon The liquid-speech-balloon (aka LIQUID SPEECH BALLOON) plugin before 1.0.7 for WordPress allows XSS with Internet Explorer. 0.9%
CVE-2017-6772 MED 4.3 cisco elastic_services_controller A vulnerability in Cisco Elastic Services Controller (ESC) could allow an authenticated, remote attacker to view sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could exploit this vulnerability by authe 0.9%
CVE-2017-3889 MED 6.1 cisco registered_envelope_service A vulnerability in the web interface of the Cisco Registered Envelope Service could allow an unauthenticated, remote attacker to redirect a user to a undesired web page, aka an Open Redirect. This vulnerability affects the Cisco Registered Envelope cloud-based 0.9%
CVE-2017-3871 MED 4.3 cisco prime_optical A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The attac 0.9%
CVE-2026-58277 HIGH 8.8 microsoft sharepoint_server Improper authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-55052 HIGH 8.8 microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2024-38204 HIGH 7.5 microsoft azure_functions Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2023-52340 HIGH 7.5 linux linux_kernel The IPv6 implementation in the Linux kernel before 6.3 has a net/ipv6/route.c max_size threshold that can be consumed easily, e.g., leading to a denial of service (network is unreachable errors) when IPv6 packets are sent in a loop via a raw socket. 0.9%
CVE-2023-29542 CRIT 9.8 mozilla firefox A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox an 0.9%
CVE-2021-22919 HIGH 7.5 citrix application_delivery_controller_firmware A vulnerability has been discovered in Citrix ADC (formerly known as NetScaler ADC) and Citrix Gateway (formerly known as NetScaler Gateway), and Citrix SD-WAN WANOP Edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO. These vulnerabilities, if exploited, co 0.9%
CVE-2021-34510 HIGH 7.8 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.9%
CVE-2021-20412 HIGH 7.5 ibm security_verify_information_queue IBM Security Verify Information Queue 1.0.6 and 1.0.7 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM 0.9%
CVE-2021-1286 MED 6.5 cisco data_center_network_manager Multiple vulnerabilities in the web-based management interface of Cisco Data Center Network Manager (DCNM) could allow a remote attacker with network-operator privileges to conduct a cross-site scripting (XSS) attack or a reflected file download (RFD) attack a 0.9%
CVE-2026-47299 HIGH 7.2 microsoft azure_monitor_agent Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2026-50663 HIGH 8.8 microsoft age_of_empires_ii Relative path traversal in Age of Empires II: Definitive Edition Game allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2025-21198 CRIT 9.0 microsoft hpc_pack_2016 Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability 0.9%
CVE-2024-30001 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability 0.9%
CVE-2023-21792 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.9%
CVE-2023-21784 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.9%
CVE-2023-21782 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.9%
CVE-2023-21780 HIGH 7.8 microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability 0.9%