57.859 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.859 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-56645 | HIGH 8.8 | microsoft edge_chromium Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2025-55238 | HIGH 7.5 | microsoft dynamics_365 Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability | 0.8% | — |
| CVE-2025-21185 | MED 6.5 | microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2024-35275 | MED 6.6 | fortinet fortianalyzer A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http request | 0.8% | — |
| CVE-2024-26188 | MED 4.3 | microsoft edge Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.8% | — |
| CVE-2022-22409 | MED 5.3 | ibm aspera_faspex IBM Aspera Faspex 5.0.5 could allow a remote attacker to gather sensitive information about the web application, caused by an insecure configuration. IBM X-Force ID: 222592. | 0.8% | — |
| CVE-2023-37579 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Function Worker. This issue affects Apache Pulsar: before 2.10.4, and 2.11.0. Any authenticated user can retrieve a source's configuration or a sink's configuration without aut | 0.8% | — |
| CVE-2023-30428 | HIGH 8.2 | apache pulsar Incorrect Authorization vulnerability in Apache Software Foundation Apache Pulsar Broker's Rest Producer allows authenticated user with a custom HTTP header to produce a message to any topic using the broker's admin role. This issue affects Apache Pulsar Broke | 0.8% | — |
| CVE-2021-39019 | MED 6.5 | ibm engineering_lifecycle_optimization_-_publishing IBM Engineering Lifecycle Optimization - Publishing 6.0.6, 6.0.6.1, 7.0, 7.0.1, and 7.0.2 could disclose highly sensitive information through an HTTP GET request to an authenticated user. IBM X-Force ID: 213728. | 0.8% | — |
| CVE-2021-33034 | HIGH 7.8 | debian debian_linux In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value. | 0.8% | — |
| CVE-2020-3406 | MED 5.4 | cisco sd-wan_firmware A vulnerability in the web-based management interface of the Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web-ba | 0.8% | — |
| CVE-2020-1293 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE- | 0.8% | — |
| CVE-2020-1278 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1257, CVE- | 0.8% | — |
| CVE-2020-1257 | HIGH 7.8 | microsoft visual_studio An elevation of privilege vulnerability exists when the Diagnostics Hub Standard Collector Service improperly handles file operations, aka 'Diagnostics Hub Standard Collector Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1278, CVE- | 0.8% | — |
| CVE-2025-21215 | MED 4.6 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.8% | — |
| CVE-2024-43561 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43559 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43558 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43557 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-43555 | MED 6.5 | microsoft windows_10_1809 Windows Mobile Broadband Driver Denial of Service Vulnerability | 0.8% | — |
| CVE-2024-26238 | HIGH 7.8 | microsoft windows_10_21h2 Microsoft PLUGScheduler Scheduled Task Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-45861 | MED 6.5 | fortinet fortios An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.9 and before 6.4.11 and FortiProxy version 7.2.0 through 7.2.1, version 7.0.0 through 7.0.7 and before 2 | 0.8% | — |
| CVE-2020-7877 | HIGH 8.0 | mastersoft zook_agent A buffer overflow issue was discovered in ZOOK solution(remote administration tool) through processing 'ConnectMe' command while parsing a crafted OUTERIP value because of missing boundary check. This vulnerability allows the attacker to execute remote arbitra | 0.8% | — |
| CVE-2021-36943 | MED 4.0 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2019-19697 | MED 6.7 | trendmicro antivirus_\+_security_2019 An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. | 0.8% | — |