57.613 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.613 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-1018 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet | 0.9% | — |
| CVE-2019-1017 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0.9% | — |
| CVE-2019-1014 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0.9% | — |
| CVE-2019-0984 | HIGH 7.0 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln | 0.9% | — |
| CVE-2019-0960 | HIGH 7.0 | microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr | 0.9% | — |
| CVE-2018-0255 | HIGH 8.8 | cisco ios A vulnerability in the device manager web interface of Cisco Industrial Ethernet Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerability is due to in | 0.9% | — |
| CVE-2017-3005 | HIGH 7.8 | adobe photoshop_cc Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. | 0.9% | — |
| CVE-2013-1199 | MED 4.9 | cisco adaptive_security_appliance Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources withi | 0.9% | — |
| CVE-2026-42779 | CRIT 9.8 | apache mina The fix for CVE-2026-41635 was not applied to the 2.1.X and 2.2.X branches. Here was the original issue description: Apache MINA's AbstractIoBuffer.resolveClass() contains two branches, one of them (for static classes or primitive types) does not ch | 0.9% | — |
| CVE-2025-48824 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-33868 | CRIT 9.8 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection. | 0.9% | — |
| CVE-2024-21382 | MED 4.3 | microsoft edge_chromium Microsoft Edge for Android Information Disclosure Vulnerability | 0.9% | — |
| CVE-2023-20010 | HIGH 8.1 | cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injecti | 0.9% | — |
| CVE-2021-26619 | HIGH 7.1 | bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. | 0.9% | — |
| CVE-2021-32591 | MED 5.3 | fortinet fortiadc A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.12, FortiADC before 6.2.1, FortiMail 7.0.1 and earlier may allow an attacker in possession of the pas | 0.9% | — |
| CVE-2019-1577 | MED 6.3 | paloaltonetworks traps Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML. | 0.9% | — |
| CVE-2017-4930 | MED 5.4 | vmware airwatch VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being red | 0.9% | — |
| CVE-2016-9250 | HIGH 7.5 | f5 big-ip_access_policy_manager In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism. | 0.9% | — |
| CVE-2015-0568 | HIGH 7.8 | linux linux_kernel Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows a | 0.9% | — |
| CVE-2010-4183 | MED 4.3 | htmlpurifier htmlpurifier Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading St | 0.9% | — |
| CVE-2026-45480 | CRIT 10.0 | microsoft azure_active_directory Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-22828 | HIGH 8.1 | fortinet fortianalyzer_cloud A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successf | 0.9% | — |
| CVE-2023-50740 | MED 5.3 | apache linkis In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module. We recommend users upgrade the version of Linkis to version 1.5.0 | 0.9% | — |
| CVE-2022-29480 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of | 0.9% | — |
| CVE-2022-29479 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, and F5 BIG-IQ Centralized Management all versions of 8.x and 7.x, when an IPv6 self IP address is configu | 0.9% | — |