57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21430 | MED 5.7 | microsoft windows_10_1507 Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-36011 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-20226 | HIGH 8.6 | cisco ios_xe A vulnerability in Application Quality of Experience (AppQoE) and Unified Threat Defense (UTD) on Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) c | 0.7% | — |
| CVE-2023-24953 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-47213 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-47212 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-44682 | MED 6.8 | microsoft windows_10 Windows Hyper-V Denial of Service Vulnerability | 0.7% | — |
| CVE-2022-38030 | MED 4.3 | microsoft windows_10 Windows USB Serial Driver Information Disclosure Vulnerability | 0.7% | — |
| CVE-2019-5594 | MED 6.1 | fortinet fortinac An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI. | 0.7% | — |
| CVE-2011-1583 | MED 6.9 | citrix xen Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overfl | 0.7% | — |
| CVE-2026-78520 | MED 6.5 | microsoft 365_apps Out-of-bounds read in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-69826 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-69773 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-69727 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-69423 | HIGH 8.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Video Driver allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-69332 | HIGH 8.0 | microsoft windows_10_1607 Out-of-bounds read in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-58597 | MED 4.3 | microsoft edge_chromium Insufficient ui warning of dangerous operations in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. | 0.7% | — |
| CVE-2025-49713 | HIGH 8.8 | microsoft edge_chromium Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2024-39726 | HIGH 8.2 | ibm engineering_lifecycle_optimization_-_engineering_insights IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume | 0.7% | — |
| CVE-2023-49250 | HIGH 7.3 | apache dolphinscheduler Because the HttpUtils class did not verify certificates, an attacker that could perform a Man-in-the-Middle (MITM) attack on outgoing https connections could impersonate the server. This issue affects Apache DolphinScheduler: before 3.2.0. Users are recommen | 0.7% | — |
| CVE-2022-44704 | HIGH 7.8 | microsoft windows_sysmon Microsoft Windows System Monitor (Sysmon) Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2022-44648 | MED 5.5 | trendmicro apex_one An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged | 0.7% | — |
| CVE-2022-44647 | MED 5.5 | trendmicro apex_one An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged | 0.7% | — |
| CVE-2022-20811 | MED 5.5 | cisco roomos Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. For more information a | 0.7% | — |
| CVE-2022-21836 | HIGH 7.8 | microsoft windows_10 Windows Certificate Spoofing Vulnerability | 0.7% | — |