IT
58.614 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.614 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2019-1132 HIGH 7.8 microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. 9.8%
CVE-2022-20701 CRIT 10.0 cisco rv340_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot 9.7%
CVE-2019-0703 MED 6.5 microsoft windows_10_1507 An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, aka 'Windows SMB Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0704, CVE-2019-0821. 9.6%
CVE-2018-0156 HIGH 7.5 cisco ios A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (DoS) condition. The vulnerability is due t 9.4%
CVE-2021-34486 HIGH 7.8 microsoft windows_10_1809 Windows Event Tracing Elevation of Privilege Vulnerability 9.3%
CVE-2025-2783 HIGH 8.3 google chrome Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromium security severity: High) 9.2%
CVE-2022-20703 CRIT 10.0 cisco rv160_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot 9.2%
CVE-2026-35616 CRIT 9.8 fortinet forticlientems A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. 9.1%
CVE-2022-23748 HIGH 7.8 audinate dante_application_library mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load mal 9.1%
CVE-2015-2291 HIGH 7.8 ransomware intel ethernet_diagnostics_driver_iqvw32.sys (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8 9.0%
CVE-2022-0995 HIGH 7.8 fedoraproject fedora An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on th 8.8%
CVE-2010-4398 HIGH 7.8 microsoft windows_7 Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges 8.7%
CVE-2019-1388 HIGH 7.8 ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the Windows Certificate Dialog when it does not properly enforce user privileges, aka 'Windows Certificate Dialog Elevation of Privilege Vulnerability'. 8.6%
CVE-2025-41244 HIGH 7.8 debian debian_linux VMware Aria Operations and VMware Tools contain a local privilege escalation vulnerability. A malicious local actor with non-administrative privileges having access to a VM with VMware Tools installed and managed by Aria Operations with SDMP enabled may exploi 8.4%
CVE-2021-28310 HIGH 7.8 microsoft windows_10_1803 Win32k Elevation of Privilege Vulnerability 8.3%
CVE-2024-38189 HIGH 8.8 microsoft 365_apps Microsoft Project Remote Code Execution Vulnerability 8.2%
CVE-2019-0676 MED 6.5 microsoft internet_explorer An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory.An attacker who successfully exploited this vulnerability could test for the presence of files on disk, aka 'Internet Explorer Information Disclosure Vul 8.1%
CVE-2019-11634 CRIT 9.8 ransomware citrix receiver Citrix Workspace App before 1904 for Windows has Incorrect Access Control. 8.1%
CVE-2021-38646 HIGH 7.8 ransomware microsoft 365_apps Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability 8.0%
CVE-2023-0386 HIGH 7.8 canonical ubuntu_linux A flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the Linux kernel’s OverlayFS subsystem in how a user copies a capable file from a nosuid mount into another mount. This uid mappi 7.9%
CVE-2025-5419 HIGH 8.8 google chrome Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) 7.8%
CVE-2018-0172 HIGH 8.6 cisco ios A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulne 7.8%
CVE-2012-2034 HIGH 7.5 adobe air Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.36 7.8%
CVE-2018-0155 HIGH 8.6 cisco ios A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causin 7.7%
CVE-2018-0174 HIGH 8.6 cisco ios A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. The vulne 7.6%