IT
57.971 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2026-42833 CRIT 9.1 microsoft dynamics_365 Improper control of generation of code ('code injection') in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to execute code over a network. 0.7%
CVE-2025-49674 HIGH 8.8 microsoft windows_server_2008 Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. 0.7%
CVE-2025-49715 HIGH 7.5 microsoft dynamics_365 Exposure of private personal information to an unauthorized actor in Dynamics 365 FastTrack Implementation Assets allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2024-41742 HIGH 7.5 ibm txseries_for_multiplatforms IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial 0.7%
CVE-2024-37984 HIGH 8.4 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.7%
CVE-2024-38605 HIGH 7.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ALSA: core: Fix NULL module pointer assignment at card init The commit 81033c6b584b ("ALSA: core: Warn on empty module") introduced a WARN_ON() for a NULL module pointer passed at snd_card o 0.7%
CVE-2024-26828 CRIT 9.4 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: cifs: fix underflow in parse_server_interfaces() In this loop, we step through the buffer and after each item we check if the size_left is greater than the minimum size we need. However, th 0.7%
CVE-2024-29989 HIGH 8.4 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0.7%
CVE-2024-30359 HIGH 7.8 foxit pdf_editor Foxit PDF Reader AcroForm 3D Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability 0.7%
CVE-2024-30349 HIGH 7.8 foxit pdf_editor Foxit PDF Reader U3D File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerab 0.7%
CVE-2023-28309 HIGH 7.6 microsoft dynamics_365 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability 0.7%
CVE-2021-1522 MED 4.3 cisco connected_mobile_experiences A vulnerability in the change password API of Cisco Connected Mobile Experiences (CMX) could allow an authenticated, remote attacker to alter their own password to a value that does not comply with the strong authentication requirements that are configured on 0.7%
CVE-2020-7812 HIGH 7.8 kaoni ezhttptrans Ezhttptrans.ocx ActiveX Control in Kaoni ezHTTPTrans 1.0.0.70 and prior versions contain a vulnerability that could allow remote attacker to download arbitrary file by setting the arguments to the activex method. This can be leveraged for code execution by reb 0.7%
CVE-2020-7806 HIGH 7.8 tobesoft xplatform Tobesoft Xplatform 9.2.2.250 and earlier version have an arbitrary code execution vulnerability by using method supported by Xplatform ActiveX Control. It allows attacker to cause remote code execution. 0.7%
CVE-2019-19167 HIGH 7.8 tobesoft nexacro Tobesoft Nexacro v2019.9.25.1 and earlier version have an arbitrary code execution vulnerability by using method supported by Nexacro14 ActiveX Control. It allows attacker to cause remote code execution. 0.7%
CVE-2020-8144 HIGH 8.4 ui unifi_video The UniFi Video Server v3.9.3 and prior (for Windows 7/8/10 x64) web interface Firmware Update functionality, under certain circumstances, does not validate firmware download destinations to ensure they are within the intended destination directory tree. It ac 0.7%
CVE-2013-6682 MED 6.4 cisco adaptive_security_appliance_software The phone-proxy implementation in Cisco Adaptive Security Appliance (ASA) Software 9.0.3.6 and earlier does not properly validate X.509 certificates, which allows remote attackers to cause a denial of service (connection-database corruption) via an invalid ent 0.7%
CVE-2026-58319 CRIT 9.1 apache doris Certain Apache Doris FE HTTP REST administrative APIs were accessible without proper authentication. An unauthenticated attacker with network access to the FE HTTP service could perform unauthorized administrative operations, potentially affecting cluster inte 0.7%
CVE-2026-35423 MED 5.4 microsoft windows_10_1607 Out-of-bounds read in Telnet Client allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2026-32151 MED 6.5 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information over a network. 0.7%
CVE-2025-21179 MED 4.8 microsoft windows_11_24h2 DHCP Client Service Denial of Service Vulnerability 0.7%
CVE-2025-21361 HIGH 7.8 microsoft office Microsoft Outlook Remote Code Execution Vulnerability 0.7%
CVE-2025-21187 HIGH 7.8 microsoft power_automate_for_desktop Microsoft Power Automate Remote Code Execution Vulnerability 0.7%
CVE-2024-43505 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7%
CVE-2024-36031 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: keys: Fix overwrite of key expiration on instantiation The expiry time of a key is unconditionally overwritten during instantiation, defaulting to turn it permanent. This causes a problem fo 0.7%