57.971 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.971 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-29106 | HIGH 7.0 | microsoft windows_10 Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-26939 | HIGH 7.0 | microsoft windows_server Storage Spaces Direct Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-21987 | MED 6.5 | vmware horizon_client VMware Workstation (16.x prior to 16.1.2) and Horizon Client for Windows (5.x prior to 5.5.2) contain out-of-bounds read vulnerability in the Cortado ThinPrint component (TTC Parser). A malicious actor with access to a virtual machine or remote desktop may be | 0.6% | — |
| CVE-2019-19689 | HIGH 7.8 | trendmicro housecall_for_home_networks Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses. | 0.6% | — |
| CVE-2019-1826 | MED 6.8 | cisco aironet_access_point_firmware A vulnerability in the quality of service (QoS) feature of Cisco Aironet Series Access Points (APs) could allow an authenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper input v | 0.6% | — |
| CVE-2018-1897 | HIGH 8.4 | ibm db2 IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5., and 11.1 db2pdcfg is vulnerable to a stack based buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 152462. | 0.6% | — |
| CVE-2016-6444 | HIGH 8.8 | cisco meeting_server A vulnerability in Cisco Meeting Server could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a Web Bridge user. More Information: CSCvb03308. Known Affected Releases: 1.8, 1.9, 2.0. | 0.6% | — |
| CVE-2026-20211 | CRIT 9.1 | A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid high-privileged administrative creden | 0.6% | — |
| CVE-2026-68834 | HIGH 8.0 | microsoft windows_10_1607 Stack-based buffer overflow in Windows NTFS allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-50426 | MED 6.8 | microsoft windows_10_1607 Relative path traversal in DNS Server allows an authorized attacker to execute code over an adjacent network. | 0.6% | — |
| CVE-2026-35438 | HIGH 8.3 | microsoft windows_admin_center Missing authorization in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-21537 | HIGH 8.8 | microsoft defender_for_endpoint Improper control of generation of code ('code injection') in Microsoft Defender for Linux allows an unauthorized attacker to execute code over an adjacent network. | 0.6% | — |
| CVE-2025-62556 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2020-29010 | MED 5.0 | fortinet fortios An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn | 0.6% | — |
| CVE-2022-40231 | MED 4.3 | ibm sterling_b2b_integrator IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.0 could allow an authenticated user to perform unauthorized actions due to improper access controls. IBM X-Force ID: 235533. | 0.6% | — |
| CVE-2023-23784 | MED 5.7 | fortinet fortiweb A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to information disclosure via specially crafted web requests. | 0.6% | — |
| CVE-2023-21694 | MED 6.8 | microsoft windows_10 Windows Fax Service Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2015-10010 | LOW 3.1 | cisco openresolve A vulnerability was found in OpenDNS OpenResolve. It has been rated as problematic. Affected by this issue is the function get of the file resolverapi/endpoints.py of the component API. The manipulation leads to cross site scripting. The attack may be launched | 0.6% | — |
| CVE-2022-20938 | MED 4.3 | cisco secure_firewall_management_center A vulnerability in the module import function of the administrative interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to view sensitive information. This vulnerability is due to insufficient validati | 0.6% | — |
| CVE-2021-42319 | MED 4.7 | microsoft visual_studio_2017 Visual Studio Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2017-18549 | MED 5.5 | linux linux_kernel An issue was discovered in drivers/scsi/aacraid/commctrl.c in the Linux kernel before 4.13. There is potential exposure of kernel stack memory because aac_send_raw_srb does not initialize the reply structure. | 0.6% | — |
| CVE-2018-14889 | HIGH 7.8 | apache couchdb CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability. | 0.6% | — |
| CVE-2004-1072 | HIGH 7.2 | linux linux_kernel The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow | 0.6% | — |
| CVE-2026-77486 | HIGH 8.8 | microsoft sql_server_2017 Integer overflow or wraparound in SQL Server allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-62706 | HIGH 8.8 | microsoft windows_10_1607 Out-of-bounds read in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | 0.6% | — |