58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36802 | HIGH 7.8 | microsoft windows_10_1809 Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | 27.9% | |
| CVE-2024-21351 | HIGH 7.6 | microsoft windows_10_1507 Windows SmartScreen Security Feature Bypass Vulnerability | 27.8% | |
| CVE-2018-8581 | HIGH 7.4 | ransomware microsoft exchange_server An elevation of privilege vulnerability exists in Microsoft Exchange Server, aka "Microsoft Exchange Server Elevation of Privilege Vulnerability." This affects Microsoft Exchange Server. | 27.4% | |
| CVE-2025-30397 | HIGH 7.5 | microsoft windows_10_1507 Access of resource using incompatible type ('type confusion') in Microsoft Scripting Engine allows an unauthorized attacker to execute code over a network. | 26.8% | |
| CVE-2024-37085 | MED 6.8 | ransomware vmware cloud_foundation VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to use AD for user management https://blogs.vmware.com/vsphere | 26.8% | |
| CVE-2014-2817 | HIGH 8.8 | microsoft internet_explorer Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability." | 26.3% | |
| CVE-2020-8196 | MED 4.3 | citrix application_delivery_controller_firmware Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 resulting in limited information disclosure to low privil | 26.3% | |
| CVE-2016-3351 | MED 6.5 | ransomware microsoft edge Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability." | 26.3% | |
| CVE-2024-49138 | HIGH 7.8 | microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 26.2% | |
| CVE-2023-20269 | MED 5.0 | ransomware cisco adaptive_security_appliance_software A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify val | 25.5% | |
| CVE-2026-20245 | HIGH 7.8 | cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute | 25.3% | |
| CVE-2024-35250 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability | 25.2% | |
| CVE-2016-7855 | HIGH 8.8 | adobe flash_player Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016. | 25.2% | |
| CVE-2022-0185 | HIGH 8.4 | linux linux_kernel A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherw | 25.2% | |
| CVE-2019-18187 | HIGH 7.5 | trendmicro officescan Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote | 25.1% | |
| CVE-2018-5002 | HIGH 7.8 | adobe flash_player Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | 25.1% | |
| CVE-2026-20122 | MED 5.4 | cisco catalyst_sd-wan_manager A vulnerability in the API of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to overwrite arbitrary files on the local file system. To exploit this vulnerability, the attacker must have valid read-only credentials with API access o | 25.0% | |
| CVE-2014-0502 | HIGH 8.8 | adobe adobe_air Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK | 24.8% | |
| CVE-2022-41128 | HIGH 8.8 | microsoft windows_10_1507 Windows Scripting Languages Remote Code Execution Vulnerability | 24.6% | |
| CVE-2016-0040 | HIGH 7.8 | microsoft windows_7 The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability." | 24.5% | |
| CVE-2026-21510 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 24.2% | |
| CVE-2020-1380 | HIGH 7.8 | microsoft internet_explorer A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current u | 24.2% | |
| CVE-2021-36948 | HIGH 7.8 | microsoft windows_10_1809 Windows Update Medic Service Elevation of Privilege Vulnerability | 23.3% | |
| CVE-2026-19490 | CRIT 9.8 | citrix netscaler_application_delivery_controller Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | 23.2% | |
| CVE-2016-6367 | HIGH 7.8 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software before 8.4(1) on ASA 5500, ASA 5500-X, PIX, and FWSM devices allows local users to gain privileges via invalid CLI commands, aka Bug ID CSCtu74257 or EPICBANANA. | 22.6% |