IT
58.587 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.587 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-35311 HIGH 8.8 microsoft 365_apps Microsoft Outlook Security Feature Bypass Vulnerability 15.5%
CVE-2026-34197 HIGH 8.8 apache activemq Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. The default Jolokia 15.5%
CVE-2015-0310 HIGH 7.8 adobe flash_player Adobe Flash Player before 13.0.0.262 and 14.x through 16.x before 16.0.0.287 on Windows and OS X and before 11.2.202.438 on Linux does not properly restrict discovery of memory addresses, which allows attackers to bypass the ASLR protection mechanism on Window 15.1%
CVE-2022-38028 HIGH 7.8 microsoft windows_10_1507 Windows Print Spooler Elevation of Privilege Vulnerability 14.9%
CVE-2022-20708 CRIT 10.0 cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot 14.9%
CVE-2015-2360 HIGH 8.8 microsoft windows_7 win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users 14.8%
CVE-2018-14634 HIGH 7.8 canonical ubuntu_linux An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x 14.7%
CVE-2024-8069 HIGH 8.0 citrix session_recording Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server 14.6%
CVE-2018-0151 CRIT 9.8 cisco ios_xe A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. The vulne 14.2%
CVE-2024-49039 HIGH 8.8 ransomware microsoft windows_10_1507 Windows Task Scheduler Elevation of Privilege Vulnerability 14.2%
CVE-2025-6554 HIGH 8.1 google chrome Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High) 14.1%
CVE-2026-76460 CRIT 10.0 cisco identity_services_engine A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this v 14.0%
CVE-2023-38180 HIGH 7.5 fedoraproject fedora .NET and Visual Studio Denial of Service Vulnerability 14.0%
CVE-2025-29824 HIGH 7.8 ransomware microsoft windows_10_1507 Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. 13.9%
CVE-2017-12240 CRIT 9.8 cisco ios The DHCP relay subsystem of Cisco IOS 12.2 through 15.6 and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. The attacker could also cause 13.8%
CVE-2016-0165 HIGH 7.8 microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application 13.7%
CVE-2024-38213 MED 6.5 microsoft windows_10_1507 Windows Mark of the Web Security Feature Bypass Vulnerability 13.6%
CVE-2023-20867 LOW 3.9 debian debian_linux A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. 13.5%
CVE-2022-22948 MED 6.5 vmware cloud_foundation The vCenter Server contains an information disclosure vulnerability due to improper permission of files. A malicious actor with non-administrative access to the vCenter Server may exploit this issue to gain access to sensitive information. 13.3%
CVE-2024-21410 CRIT 9.8 microsoft exchange_server Microsoft Exchange Server Elevation of Privilege Vulnerability 12.6%
CVE-2022-20775 HIGH 7.8 cisco catalyst_sd-wan_manager A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to gain elevated privileges. This vulnerability is due to improper access controls on commands within the application CLI. An attacker could exploit this vulner 12.5%
CVE-2023-36424 HIGH 7.8 microsoft windows_10_1507 Windows Common Log File System Driver Elevation of Privilege Vulnerability 12.2%
CVE-2023-21715 HIGH 7.3 microsoft 365_apps Microsoft Publisher Security Feature Bypass Vulnerability 12.0%
CVE-2017-11292 HIGH 8.8 adobe flash_player Adobe Flash Player version 27.0.0.159 and earlier has a flawed bytecode verification procedure, which allows for an untrusted value to be used in the calculation of an array index. This can lead to type confusion, and successful exploitation could lead to arbi 11.9%
CVE-2020-3118 HIGH 8.8 cisco ios_xr A vulnerability in the Cisco Discovery Protocol implementation for Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to execute arbitrary code or cause a reload on an affected device. The vulnerability is due to improper validation of str 11.7%