57.808 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.808 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-16998 | HIGH 7.0 | microsoft windows_10 DirectX Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2020-12815 | MED 5.4 | fortinet fortianalyzer An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields. | 0.9% | — |
| CVE-2017-5051 | HIGH 8.8 | google chrome An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer. | 0.9% | — |
| CVE-2025-25006 | MED 5.3 | microsoft exchange_server Improper handling of additional special element in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.9% | — |
| CVE-2025-21323 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2025-21317 | MED 5.5 | microsoft windows_10_21h2 Windows Kernel Memory Information Disclosure Vulnerability | 0.9% | — |
| CVE-2024-32117 | MED 4.9 | fortinet fortianalyzer An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData ver | 0.9% | — |
| CVE-2021-31937 | HIGH 8.2 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2022-43284 | HIGH 7.5 | f5 njs Nginx NJS v0.7.2 to v0.7.4 was discovered to contain a segmentation violation via njs_scope_valid_value at njs_scope.h. NOTE: the vendor disputes the significance of this report because NJS does not operate on untrusted input. | 0.9% | — |
| CVE-2022-38005 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.9% | — |
| CVE-2017-12347 | MED 6.1 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client inter | 0.9% | — |
| CVE-2017-12346 | MED 6.1 | cisco data_center_network_manager Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client inter | 0.9% | — |
| CVE-2017-2307 | MED 6.1 | juniper junos_space A reflected cross site scripting vulnerability in the administrative interface of Juniper Networks Junos Space versions prior to 16.1R1 may allow remote attackers to steal sensitive information or perform certain administrative actions on Junos Space. | 0.9% | — |
| CVE-2016-4930 | MED 6.1 | juniper junos_space Cross-site scripting (XSS) vulnerability in Junos Space before 15.2R2 allows remote attackers to steal sensitive information or perform certain administrative actions. | 0.9% | — |
| CVE-2016-6365 | MED 6.1 | cisco secure_firewall_management_center Cross-site scripting (XSS) vulnerability in Cisco Firepower Management Center 4.10.3, 5.2.0, 5.3.0, 5.3.0.2, 5.3.1, and 5.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCur25508 and CSCur25518. | 0.9% | — |
| CVE-2016-1323 | MED 4.3 | cisco spark The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048. | 0.9% | — |
| CVE-2025-22254 | MED 6.6 | fortinet fortios An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4.0 through 6.4.15, FortiProxy 7.6.0 through 7.6. | 0.8% | — |
| CVE-2024-38105 | MED 6.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-38102 | MED 6.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-38101 | MED 6.5 | microsoft windows_10_1507 Windows Layer-2 Bridge Network Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2023-52776 | HIGH 8.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix dfs-radar and temperature event locking The ath12k active pdevs are protected by RCU but the DFS-radar and temperature event handling code calling ath12k_mac_get_ar_by_pdev | 0.8% | — |
| CVE-2024-21384 | HIGH 7.8 | microsoft 365_apps Microsoft Office OneNote Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-5717 | HIGH 7.8 | linux linux_kernel A heap out-of-bounds write vulnerability in the Linux kernel's Linux Kernel Performance Events (perf) component can be exploited to achieve local privilege escalation. If perf_read_group() is called while an event's sibling_list is smaller than its child's si | 0.8% | — |
| CVE-2023-30991 | HIGH 7.5 | ibm db2 IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 254037. | 0.8% | — |
| CVE-2022-41052 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Remote Code Execution Vulnerability | 0.8% | — |