57.620 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.620 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-27181 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP APM 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when APM is configured on a virtual server and the associated acce | 0.9% | — |
| CVE-2022-26130 | MED 5.3 | f5 big-ip_access_policy_manager On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, and 13.1.x versions prior to 13.1.5, when an Active mode-enabled FTP profile is configured on a virtual server, undisclosed traffic can cause | 0.9% | — |
| CVE-2021-43247 | HIGH 7.8 | microsoft windows_10 Windows TCP/IP Driver Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2021-1640 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-17070 | HIGH 7.8 | microsoft windows_10 Windows Update Medic Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1584 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the dnsrslvr.dll handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. To exploit the vulnerability, a locally authentica | 0.9% | — |
| CVE-2020-1529 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then inst | 0.9% | — |
| CVE-2020-1520 | HIGH 7.8 | microsoft windows_10 A remote code execution vulnerability exists when the Windows Font Driver Host improperly handles memory. An attacker who successfully exploited the vulnerability would gain execution on a victim system. The security update addresses the vulnerability by corre | 0.9% | — |
| CVE-2020-1480 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then inst | 0.9% | — |
| CVE-2020-1479 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when DirectX improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delet | 0.9% | — |
| CVE-2020-1429 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. | 0.9% | — |
| CVE-2018-2021 | MED 6.1 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | 0.9% | — |
| CVE-2012-6396 | MED 4.9 | cisco nexus_7000 Cisco NX-OS on Nexus 7000 series switches does not properly handle certain line-card replacements, which might allow remote authenticated users to cause a denial of service (memory consumption) via a crafted configuration that references interfaces that do not | 0.9% | — |
| CVE-2023-29326 | HIGH 7.8 | microsoft .net_framework .NET Framework Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2022-21921 | MED 4.4 | microsoft windows_10 Windows Defender Credential Guard Security Feature Bypass Vulnerability | 0.9% | — |
| CVE-2021-1073 | HIGH 8.3 | nvidia geforce_experience NVIDIA GeForce Experience, all versions prior to 3.23, contains a vulnerability in the login flow when a user tries to log in by using a browser, while, at the same time, any other web page is loaded in other tabs of the same browser. In this situation, the we | 0.9% | — |
| CVE-2020-17073 | HIGH 7.8 | microsoft windows_10 Windows Update Orchestrator Service Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-1243 | HIGH 7.8 | microsoft windows_10 <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged accoun | 0.9% | — |
| CVE-2020-16980 | HIGH 7.8 | microsoft windows_server_2012 <p>An elevation of privilege vulnerability exists when the Windows iSCSI Target Service improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attack | 0.9% | — |
| CVE-2020-16936 | HIGH 7.8 | microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia | 0.9% | — |
| CVE-2020-12818 | MED 5.3 | fortinet fortios An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed. | 0.9% | — |
| CVE-2020-3246 | MED 4.3 | cisco umbrella A vulnerability in the web server of Cisco Umbrella could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user of an affected service. The vulnerability is due to insufficient validation of use | 0.9% | — |
| CVE-2025-69269 | CRIT 9.8 | broadcom dx_netops_spectrum Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux allows OS Command Injection.This issue affects DX NetOps Spectrum: 23.3.6 and earlier. | 0.9% | — |
| CVE-2025-47998 | HIGH 8.8 | microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | 0.9% | — |
| CVE-2024-41138 | HIGH 7.1 | microsoft teams A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library can leverage Teams's access privileges, leading to a permission bypas | 0.9% | — |