57.921 CVE tracked
783 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.921 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1703 | HIGH 7.8 | microsoft windows_10 Windows Event Logging Service Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-1650 | HIGH 7.8 | microsoft windows_10 Windows Runtime C++ Template Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2017-7374 | HIGH 7.8 | linux linux_kernel Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing | 0.8% | — |
| CVE-2026-68785 | MED 4.9 | microsoft sql_server_2017 Heap-based buffer overflow in SQL Server allows an authorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-64878 | CRIT 9.9 | tenable security_center Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. | 0.8% | — |
| CVE-2024-21760 | HIGH 8.4 | fortinet fortisoar An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitra | 0.8% | — |
| CVE-2024-55532 | CRIT 9.8 | apache ranger Improper Neutralization of Formula Elements in Export CSV feature of Apache Ranger in Apache Ranger Version < 2.6.0. Users are recommended to upgrade to version 2.6.0, which fixes this issue. | 0.8% | — |
| CVE-2024-45626 | MED 6.5 | apache james_server Apache James server JMAP HTML to text plain implementation in versions below 3.8.2 and 3.7.6 is subject to unbounded memory consumption that can result in a denial of service. Users are recommended to upgrade to version 3.7.6 and 3.8.2, which fix this issue. | 0.8% | — |
| CVE-2023-37931 | HIGH 8.8 | fortinet fortivoice An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker to perform a blind sql injection attack via se | 0.8% | — |
| CVE-2022-41051 | HIGH 7.8 | microsoft azure_rtos_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2022-22977 | HIGH 7.1 | vmware tools VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is installed, may exploit this issue leading to | 0.8% | — |
| CVE-2022-30594 | HIGH 7.8 | debian debian_linux The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag. | 0.8% | — |
| CVE-2001-0161 | MED 5.0 | cisco aironet Cisco 340-series Aironet access point using firmware 11.01 does not use 6 of the 24 available IV bits for WEP encryption, which makes it easier for remote attackers to mount brute force attacks. | 0.8% | — |
| CVE-2026-21253 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-53477 | HIGH 7.5 | apache nimble NULL Pointer Dereference vulnerability in Apache Nimble. Missing validation of HCI connection complete or HCI command TX buffer could lead to NULL pointer dereference. This issue requires disabled asserts and broken or bogus Bluetooth controller and thus seve | 0.8% | — |
| CVE-2025-26642 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2022-37376 | LOW 3.3 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.8% | — |
| CVE-2022-23013 | HIGH 8.8 | f5 big-ip_domain_name_system On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility | 0.8% | — |
| CVE-2020-3367 | HIGH 7.8 | cisco asyncos A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability | 0.8% | — |
| CVE-2019-1920 | HIGH 7.4 | cisco access_points A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a | 0.8% | — |
| CVE-2018-6661 | HIGH 7.8 | mcafee true_key DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain privilege elevation via not verifying a particular DLL file signature. | 0.8% | — |
| CVE-2017-6659 | HIGH 8.8 | cisco prime_collaboration_assurance A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Informa | 0.8% | — |
| CVE-2017-6634 | HIGH 8.8 | cisco industrial_ethernet_1000_series_firmware A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerabil | 0.8% | — |
| CVE-2015-4481 | LOW 3.3 | mozilla firefox Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during | 0.8% | — |
| CVE-2026-69724 | HIGH 8.8 | microsoft sharepoint_server Missing authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | 0.8% | — |