IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-20668 MED 6.1 cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul 0.7%
CVE-2022-20667 MED 6.1 cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul 0.7%
CVE-2022-20666 MED 6.1 cisco common_services_platform_collector Multiple vulnerabilities in the web-based management interface of Cisco Common Services Platform Collector (CSPC) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vul 0.7%
CVE-2021-3743 HIGH 7.1 fedoraproject fedora An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information 0.7%
CVE-2021-3062 HIGH 8.1 paloaltonetworks pan-os An improper access control vulnerability in PAN-OS software enables an attacker with authenticated access to GlobalProtect portals and gateways to connect to the EC2 instance metadata endpoint for VM-Series firewalls hosted on Amazon AWS. Exploitation of this 0.7%
CVE-2020-1461 HIGH 7.1 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu 0.7%
CVE-2020-5889 MED 5.4 f5 big-ip_access_policy_manager On versions 15.1.0-15.1.0.1, 15.0.0-15.0.1.2, and 14.1.0-14.1.2.3, in BIG-IP APM portal access, a specially crafted HTTP request can lead to reflected XSS after the BIG-IP APM system rewrites the HTTP response from the untrusted backend server and sends it to 0.7%
CVE-2018-0005 HIGH 7.4 juniper junos QFX and EX Series switches configured to drop traffic when the MAC move limit is exceeded will forward traffic instead of dropping traffic. This can lead to denials of services or other unintended conditions. Affected releases are Juniper Networks Junos OS: 14 0.7%
CVE-2016-6457 MED 6.5 cisco application_policy_infrastructure_controller A vulnerability in the Cisco Nexus 9000 Series Platform Leaf Switches for Application Centric Infrastructure (ACI) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability affects 0.7%
CVE-2026-33823 CRIT 9.6 microsoft teams Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network. 0.7%
CVE-2026-20096 MED 6.5 cisco enterprise_nfv_infrastructure_software A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. Thi 0.7%
CVE-2026-21235 HIGH 7.3 microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2025-60728 MED 4.3 microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. 0.7%
CVE-2025-53149 HIGH 7.8 microsoft windows_10_1507 Heap-based buffer overflow in Kernel Streaming WOW Thunk Service Driver allows an authorized attacker to elevate privileges locally. 0.7%
CVE-2024-53226 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() ib_map_mr_sg() allows ULPs to specify NULL as the sg_offset argument. The driver needs to check whether it is a NULL pointer bef 0.7%
CVE-2024-38155 MED 5.5 microsoft windows_10_1809 Security Center Broker Information Disclosure Vulnerability 0.7%
CVE-2023-47104 CRIT 9.8 vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered s 0.7%
CVE-2023-32018 HIGH 7.8 microsoft windows_11_22h2 Windows Hello Remote Code Execution Vulnerability 0.7%
CVE-2023-32008 HIGH 7.8 microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability 0.7%
CVE-2023-29370 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0.7%
CVE-2023-29367 HIGH 7.8 microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability 0.7%
CVE-2023-29366 HIGH 7.8 microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability 0.7%
CVE-2023-29365 HIGH 7.8 microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability 0.7%
CVE-2022-45052 HIGH 8.8 axiell iguana A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server. 0.7%
CVE-2022-20810 MED 6.5 cisco ios_xe A vulnerability in the Simple Network Management Protocol (SNMP) of Cisco IOS XE Wireless Controller Software for the Catalyst 9000 Family could allow an authenticated, remote attacker to access sensitive information. This vulnerability is due to insufficient 0.7%