IT
57.588 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.588 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-56646 MED 6.5 microsoft edge_chromium Exposure of sensitive information to an unauthorized actor in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.9%
CVE-2026-50519 MED 6.5 microsoft github_copilot_chat Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2026-41104 CRIT 10.0 microsoft planetary_computer Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2025-30390 CRIT 9.9 microsoft azure_machine_learning Improper authorization in Azure allows an authorized attacker to elevate privileges over a network. 0.9%
CVE-2025-27736 MED 5.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Power Dependency Coordinator allows an authorized attacker to disclose information locally. 0.9%
CVE-2024-42284 CRIT 9.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tipc: Return non-zero value from tipc_udp_addr2str() on error tipc_udp_addr2str() should return non-zero value if the UDP media address is invalid. Otherwise, a buffer overflow access can oc 0.9%
CVE-2024-30326 HIGH 7.8 foxit pdf_editor Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in th 0.9%
CVE-2023-29344 HIGH 7.8 microsoft 365_apps Microsoft Office Remote Code Execution Vulnerability 0.9%
CVE-2022-35832 MED 5.5 microsoft windows_10 Windows Event Tracing Denial of Service Vulnerability 0.9%
CVE-2021-33624 MED 4.7 debian debian_linux In kernel/bpf/verifier.c in the Linux kernel before 5.12.13, a branch can be mispredicted (e.g., because of type confusion) and consequently an unprivileged BPF program can read arbitrary memory locations via a side-channel attack, aka CID-9183671af6db. 0.9%
CVE-2020-0783 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0781. 0.9%
CVE-2020-0781 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Universal Plug and Play (UPnP) service improperly handles objects in memory, aka 'Windows UPnP Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0783. 0.9%
CVE-2020-0641 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Media Service that allows file creation in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Windows Elevation of Privilege Vulnerabi 0.9%
CVE-2018-15451 MED 5.4 cisco prime_service_catalog A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to 0.9%
CVE-2018-15423 MED 4.7 cisco hyperflex_hx_data_platform A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulnerability is due to insufficient input validation of iFrame data in HTTP requests t 0.9%
CVE-2017-6156 MED 6.4 f5 big-ip_access_policy_manager When the F5 BIG-IP 12.1.0-12.1.1, 11.6.0-11.6.1, 11.5.1-11.5.5, or 11.2.1 system is configured with a wildcard IPSec tunnel endpoint, it may allow a remote attacker to disrupt or impersonate the tunnels that have completed phase 1 IPSec negotiations. The attac 0.9%
CVE-2026-47284 MED 6.5 microsoft visual_studio_code Exposure of sensitive information to an unauthorized actor in Visual Studio Code allows an unauthorized attacker to disclose information over a network. 0.9%
CVE-2025-49657 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.9%
CVE-2024-49087 MED 4.6 microsoft windows_10_1809 Windows Mobile Broadband Driver Information Disclosure Vulnerability 0.9%
CVE-2023-36591 HIGH 7.3 microsoft windows_10 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 0.9%
CVE-2022-3523 MED 5.3 linux linux_kernel A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is an unknown function of the file mm/memory.c of the component Driver Handler. The manipulation leads to use after free. It is possible to launch the attack remotely. I 0.9%
CVE-2021-22993 HIGH 8.8 f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and BIG-IP ASM versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.6, and 12.1.x before 12.1.5.3, DOM-based XSS on DoS Profile properties page. Note: Software versions which have reached En 0.9%
CVE-2020-17034 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%
CVE-2020-17031 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%
CVE-2020-17027 HIGH 7.8 microsoft windows_10 Windows Remote Access Elevation of Privilege Vulnerability 0.9%