IT
57.551 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.551 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2010-1971 MED 6.8 hp insight_software_installer Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968. 0.9%
CVE-2010-1968 MED 6.8 hp insight_software_installer Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971. 0.9%
CVE-2025-21365 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.9%
CVE-2024-20424 CRIT 9.9 cisco secure_firewall_management_center A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operat 0.9%
CVE-2023-38164 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.9%
CVE-2022-20688 MED 5.3 cisco ata_190_firmware A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device and cause Cisco Discovery Protocol service t 0.9%
CVE-2022-37400 HIGH 8.8 apache openoffice Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vecto 0.9%
CVE-2021-20431 MED 6.5 ibm i2_analysts_notebook IBM i2 Analyst's Notebook Premium 9.2.0, 9.2.1, and 9.2.2 does not invalidate session after logout which could allow an an attacker to obtain sensitive information from the system. IBM X-Force ID: 196342. 0.9%
CVE-2020-11492 HIGH 7.8 docker docker_desktop An issue was discovered in Docker Desktop through 2.2.0.5 on Windows. If a local attacker sets up their own named pipe prior to starting Docker with the same name, this attacker can intercept a connection attempt from Docker Service (which runs as SYSTEM), and 0.9%
CVE-2020-9343 MED 6.5 signotec signopad-api\/web An issue was discovered in signotec signoPAD-API/Web (formerly Websocket Pad Server) before 3.1.1 on Windows. It is possible to perform a Denial of Service attack because the implementation doesn't limit the parsing of nested JSON structures. If a victim visit 0.9%
CVE-2016-6154 MED 6.1 watchguard fireware The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect). 0.9%
CVE-2017-12335 MED 6.3 cisco nx-os A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command arguments. An attacker could exploit this vulnera 0.9%
CVE-2014-2845 MED 5.9 cyberduck cyberduck Cyberduck before 4.4.4 on Windows does not properly validate X.509 certificate chains, which allows man-in-the-middle attackers to spoof FTP-SSL servers via a certificate issued by an arbitrary root Certification Authority. 0.9%
CVE-2016-1465 MED 6.5 cisco nx-os Cisco Nexus 1000v Application Virtual Switch (AVS) devices before 5.2(1)SV3(1.5i) allow remote attackers to cause a denial of service (ESXi hypervisor crash and purple screen) via a crafted Cisco Discovery Protocol packet that triggers an out-of-bounds memory 0.9%
CVE-2007-5633 HIGH 7.2 almico speedfan Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C402 0.9%
CVE-2026-62800 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Windows SMB Server allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-62784 HIGH 8.8 microsoft windows_10_1607 Heap-based buffer overflow in Microsoft Local Security Authority Server (lsasrv) allows an authorized attacker to execute code over a network. 0.9%
CVE-2026-40858 HIGH 8.8 apache camel The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache use 0.9%
CVE-2025-21362 HIGH 8.4 microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability 0.9%
CVE-2024-49093 HIGH 8.8 microsoft windows_11_24h2 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability 0.9%
CVE-2023-49198 HIGH 7.5 apache seatunnel Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue 0.9%
CVE-2022-48788 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme-rdma: fix possible use-after-free in transport error_recovery work While nvme_rdma_submit_async_event_work is checking the ctrl and queue state before preparing the AER command and sche 0.9%
CVE-2024-35200 MED 5.3 f5 nginx_open_source When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate. 0.9%
CVE-2023-38139 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.9%
CVE-2022-34686 MED 5.5 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Information Disclosure Vulnerability 0.9%