57.811 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.811 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-49083 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-35254 | HIGH 7.1 | microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-26176 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-20344 | MED 5.3 | cisco imm_management_package A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI | 0.8% | — |
| CVE-2023-21748 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2023-21675 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-36172 | MED 4.3 | fortinet fortiportal An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbi | 0.8% | — |
| CVE-2021-29968 | HIGH 8.1 | mozilla firefox When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1. | 0.8% | — |
| CVE-2007-4497 | MED 5.5 | canonical ubuntu_linux Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server be | 0.8% | — |
| CVE-2025-21292 | HIGH 8.8 | microsoft windows_10_1809 Windows Search Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-21442 | HIGH 7.8 | microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-21434 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-20844 | MED 5.3 | cisco sd-wan A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC using a default static username and password co | 0.8% | — |
| CVE-2021-1517 | MED 5.0 | cisco webex_meetings_online A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the mul | 0.8% | — |
| CVE-2019-3591 | LOW 3.9 | mcafee data_loss_prevention_endpoint Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in | 0.8% | — |
| CVE-2015-1044 | LOW 3.3 | vmware esxi vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors. | 0.8% | — |
| CVE-2026-21516 | HIGH 8.8 | microsoft github_copilot Improper neutralization of special elements used in a command ('command injection') in Github Copilot allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-55333 | MED 6.1 | microsoft windows_10_1507 Incomplete comparison with missing factors in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.8% | — |
| CVE-2023-33139 | MED 5.5 | microsoft visual_studio Visual Studio Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-47211 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-41063 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2021-23037 | CRIT 9.6 | f5 big-ip_access_policy_manager On all versions of 16.1.x, 16.0.x, 15.1.x, 14.1.x, 13.1.x, 12.1.x, and 11.6.x, a reflected cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context o | 0.8% | — |
| CVE-2020-5944 | MED 4.3 | f5 big-iq_centralized_management In BIG-IQ 7.1.0, accessing the DoS Summary events and DNS Overview pages in the BIG-IQ system interface returns an error message due to disabled Grafana reverse proxy in web service configuration. F5 has done further review of this vulnerability and has re-cla | 0.8% | — |
| CVE-2015-6378 | MED 6.8 | cisco dpq3925_8x4_docsis_3.0_wireless_residential_gateway_with_embedded_digital_voice_adapter Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943. | 0.8% | — |
| CVE-2015-4274 | MED 6.8 | cisco unified_intelligence_center Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified Intelligence Center 10.0(1) and 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuu94862 and CSCuu97936. | 0.8% | — |