57.970 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.970 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-15772 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000285e9 | 0.8% | — |
| CVE-2017-15803 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address is used | 0.8% | — |
| CVE-2017-15802 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls | 0.8% | — |
| CVE-2017-15801 | HIGH 7.8 | xnview xnview XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dll file that is mishandled during an attempt to render the DLL icon, related to "Data from Faulting Address controls | 0.8% | — |
| CVE-2015-0707 | LOW 3.5 | cisco firesight_system_software Cross-site scripting (XSS) vulnerability in Cisco FireSIGHT System Software 5.3.1.1 and 6.0.0 in FireSIGHT Management Center allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCus85425. | 0.8% | — |
| CVE-2013-5541 | LOW 3.5 | cisco identity_services_engine Cross-site scripting (XSS) vulnerability in the file-upload interface in Cisco Identity Services Engine (ISE) allows remote authenticated users to inject arbitrary web script or HTML via a crafted filename, aka Bug ID CSCui67495. | 0.8% | — |
| CVE-2013-1244 | LOW 3.5 | cisco webex_social Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199. | 0.8% | — |
| CVE-2026-70124 | MED 5.9 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-69930 | MED 5.9 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-69929 | MED 5.9 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2026-69803 | MED 5.9 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an unauthorized attacker to disclose information over a network. | 0.8% | — |
| CVE-2025-65041 | CRIT 10.0 | microsoft partner_center Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2025-29820 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2025-21358 | HIGH 7.8 | microsoft windows_10_1507 Windows Core Messaging Elevation of Privileges Vulnerability | 0.8% | — |
| CVE-2022-20633 | MED 5.3 | cisco enterprise_chat_and_email A vulnerability in the web-based management interface of Cisco ECE could allow an unauthenticated, remote attacker to perform a username enumeration attack against an affected device. This vulnerability is due to differences in authentication responses | 0.8% | — |
| CVE-2023-20173 | MED 4.9 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To e | 0.8% | — |
| CVE-2020-5927 | MED 6.1 | f5 big-ip_application_security_manager In versions 15.1.0-15.1.0.4, 15.0.0-15.0.1.3, and 14.1.0-14.1.2.6, BIG-IP ASM Configuration utility Stored-Cross Site Scripting. | 0.8% | — |
| CVE-2018-10881 | MED 4.2 | canonical ubuntu_linux A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image. | 0.8% | — |
| CVE-2016-4106 | HIGH 7.8 | adobe acrobat Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privilege | 0.8% | — |
| CVE-2014-3273 | MED 6.1 | cisco ios The LLDP implementation in Cisco IOS allows remote attackers to cause a denial of service (device reload) via a malformed packet, aka Bug ID CSCum96282. | 0.8% | — |
| CVE-2004-0415 | LOW 2.1 | linux linux_kernel Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory. | 0.8% | — |
| CVE-2024-57791 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: check return value of sock_recvmsg when draining clc data When receiving clc msg, the field length in smc_clc_msg_hdr indicates the length of msg should be received from network and | 0.8% | — |
| CVE-2024-38161 | MED 6.8 | microsoft windows_10_1809 Windows Mobile Broadband Driver Remote Code Execution Vulnerability | 0.8% | — |
| CVE-2023-36554 | HIGH 8.1 | fortinet fortimanager A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or commands via specially crafted HTTP requ | 0.8% | — |
| CVE-2022-22458 | MED 6.3 | ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.0.1 stores user credentials in plain clear text which can be read by a remote authenticated user. IBM X-Force ID: 225009. | 0.8% | — |