IT
57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

57.971 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-46717 HIGH 7.5 fortinet fortios An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when configured with FortiAuthenticator in HA may allow a readonly user to gain read-write access via successive log 0.6%
CVE-2023-0977 MED 6.7 trellix agent A heap-based overflow vulnerability in Trellix Agent (Windows and Linux) version 5.7.8 and earlier, allows a remote user to alter the page heap in the macmnsvc process memory block resulting in the service becoming unavailable. 0.6%
CVE-2022-26120 MED 5.4 fortinet fortiadc Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interface 7.0.0 through 7.0.1, 5.0.0 through 6.2.2 may allow an authenticated attacker to execute unauthorized code or 0.6%
CVE-2022-21834 HIGH 7.0 microsoft windows_10 Windows User-mode Driver Framework Reflector Driver Elevation of Privilege Vulnerability 0.6%
CVE-2022-21833 HIGH 7.8 microsoft windows_10 Virtual Machine IDE Drive Elevation of Privilege Vulnerability 0.6%
CVE-2021-34536 HIGH 7.8 microsoft windows_10 Windows Storage Spaces Controller Elevation of Privilege Vulnerability 0.6%
CVE-2021-34445 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6%
CVE-2021-33773 HIGH 7.8 microsoft windows_10 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability 0.6%
CVE-2021-1374 MED 4.8 cisco ios_xe A vulnerability in the web-based management interface of Cisco IOS XE Wireless Controller software for the Catalyst 9000 Family of switches could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against another user of the 0.6%
CVE-2020-24439 LOW 2.8 adobe acrobat Acrobat Reader DC for macOS versions 2020.012.20048 (and earlier), 2020.001.30005 (and earlier) and 2017.011.30175 (and earlier) are affected by a security feature bypass. While the practical security impact is minimal, a defense-in-depth fix has been implemen 0.6%
CVE-2014-8884 MED 6.1 linux linux_kernel Stack-based buffer overflow in the ttusbdecfe_dvbs_diseqc_send_master_cmd function in drivers/media/usb/ttusb-dec/ttusbdecfe.c in the Linux kernel before 3.17.4 allows local users to cause a denial of service (system crash) or possibly gain privileges via a la 0.6%
CVE-2026-69852 HIGH 7.5 microsoft windows_10_1607 Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine 0.6%
CVE-2025-62559 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-62558 HIGH 7.8 microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. 0.6%
CVE-2025-55320 MED 6.8 microsoft configuration_manager_2403 Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. 0.6%
CVE-2024-43554 MED 5.5 microsoft windows_10_1507 Windows Kernel-Mode Driver Information Disclosure Vulnerability 0.6%
CVE-2024-43509 HIGH 7.8 microsoft windows_10_1507 Windows Graphics Component Elevation of Privilege Vulnerability 0.6%
CVE-2024-35916 MED 5.3 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: dma-buf: Fix NULL pointer dereference in sanitycheck() If due to a memory allocation failure mock_chain() returns NULL, it is passed to dma_fence_enable_sw_signaling() resulting in NULL poin 0.6%
CVE-2024-30027 HIGH 7.8 microsoft windows_10_1507 NTFS Elevation of Privilege Vulnerability 0.6%
CVE-2024-21431 HIGH 7.8 microsoft windows_10_21h2 Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability 0.6%
CVE-2023-20891 MED 6.5 vmware isolation_segment The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system 0.6%
CVE-2021-29776 MED 4.3 ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3, 7.4, and 7.5 could allow an authenticated user to obtain sensitive information from another user's dashboard providing the dashboard ID of that user. IBM X-Force ID: 203030. 0.6%
CVE-2021-0244 HIGH 7.4 juniper junos A signal handler race condition exists in the Layer 2 Address Learning Daemon (L2ALD) of Juniper Networks Junos OS due to the absence of a specific protection mechanism to avoid a race condition which may allow an attacker to bypass the storm-control feature o 0.6%
CVE-2020-4165 MED 5.4 ibm security_guardium_insights IBM Security Guardium Insights 2.0.1 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and po 0.6%
CVE-2019-0011 MED 6.5 juniper junos The Junos OS kernel crashes after processing a specific incoming packet to the out of band management interface (such as fxp0, me0, em0, vme0) destined for another address. By continuously sending this type of packet, an attacker can repeatedly crash the kerne 0.6%