IT
57.924 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.924 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2024-30064 HIGH 8.8 microsoft windows_server_2022 Windows Kernel Elevation of Privilege Vulnerability 0.8%
CVE-2023-35309 HIGH 7.5 microsoft windows_10_1507 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability 0.8%
CVE-2023-33154 HIGH 7.8 microsoft windows_10_1507 Windows Partition Management Driver Elevation of Privilege Vulnerability 0.8%
CVE-2020-27725 MED 4.3 f5 big-ip_domain_name_system In version 15.1.0-15.1.0.5, 14.1.0-14.1.3, 13.1.0-13.1.3.4, 12.1.0-12.1.5.2, and 11.6.1-11.6.5.2 of BIG-IP DNS, GTM, and Link Controller, zxfrd leaks memory when listing DNS zones. Zones can be listed via TMSH, iControl or SNMP; only users with access to those 0.8%
CVE-2016-5202 CRIT 9.1 google chrome browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data t 0.8%
CVE-2016-2084 HIGH 7.4 f5 big-ip_access_policy_manager F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 build 685-HF10, 11.5.1 before build 10.104.180, 11.5.2 before 11.5.4 build 0.1.256, 11.6.0 before build 6.204.442, and 12.0.0 before build 1.14.628; BIG-IP AAM 11.4. 0.8%
CVE-2026-66303 MED 6.5 microsoft skype_for_business_server Null pointer dereference in Skype for Business allows an authorized attacker to deny service over a network. 0.8%
CVE-2026-67633 MED 6.5 microsoft sql_server_2017 Out-of-bounds read in SQL Server allows an authorized attacker to deny service over a network. 0.8%
CVE-2025-4615 HIGH 7.2 paloaltonetworks pan-os An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and execute arbitrary commands. The security risk posed by this issu 0.8%
CVE-2024-38198 HIGH 7.5 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 0.8%
CVE-2024-38056 MED 5.5 microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0.8%
CVE-2024-38055 MED 5.5 microsoft windows_10_1507 Microsoft Windows Codecs Library Information Disclosure Vulnerability 0.8%
CVE-2022-41064 MED 5.8 microsoft .net_framework .NET Framework Information Disclosure Vulnerability 0.8%
CVE-2022-23263 HIGH 7.7 microsoft edge_chromium Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability 0.8%
CVE-2021-26442 HIGH 7.0 microsoft windows_10 Windows HTTP.sys Elevation of Privilege Vulnerability 0.8%
CVE-2021-3045 MED 4.9 paloaltonetworks pan-os An OS command argument injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator to read any arbitrary file from the file system. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.19; PAN-OS 9.0 0.8%
CVE-2021-26890 HIGH 7.8 microsoft windows_10 Application Virtualization Remote Code Execution Vulnerability 0.8%
CVE-2020-1660 HIGH 8.3 juniper junos When DNS filtering is enabled on Juniper Networks Junos MX Series with one of the following cards MS-PIC, MS-MIC or MS-MPC, an incoming stream of packets processed by the Multiservices PIC Management Daemon (mspmand) process, responsible for managing "URL Filt 0.8%
CVE-2020-3384 HIGH 8.2 cisco data_center_network_manager A vulnerability in specific REST API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system with the privileges of the logged-in user. The vulnerabilit 0.8%
CVE-2018-0208 MED 5.4 cisco email_encryption A vulnerability in the web-based management interface of the (cloud based) Cisco Registered Envelope Service could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of th 0.8%
CVE-2026-43499 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rtmutex: Use waiter::task instead of current in remove_waiter() remove_waiter() is used by the slowlock paths, but it is also used for proxy-lock rollback in rt_mutex_start_proxy_lock() when 0.8%
CVE-2026-40415 HIGH 8.1 microsoft windows_10_1809 Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network. 0.8%
CVE-2025-4598 MED 4.7 debian debian_linux A vulnerability was found in systemd-coredump. This flaw allows an attacker to force a SUID process to crash and replace it with a non-SUID binary to access the original's privileged process coredump, allowing the attacker to read sensitive data, such as /etc/ 0.8%
CVE-2024-49996 CRIT 9.4 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: cifs: Fix buffer overflow when parsing NFS reparse points ReparseDataLength is sum of the InodeType size and DataBuffer size. So to get DataBuffer size it is needed to subtract InodeType's s 0.8%
CVE-2022-45412 HIGH 8.8 mozilla firefox When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems 0.8%