58.617 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.617 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-24990 | HIGH 7.8 | microsoft windows_10_1507 Microsoft is aware of vulnerabilities in the third party Agere Modem driver that ships natively with supported Windows operating systems. This is an announcement of the upcoming removal of ltmdm64.sys driver. The driver has been removed in the October cumula | 6.4% | |
| CVE-2024-38106 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 6.3% | |
| CVE-2024-38014 | HIGH 7.8 | microsoft windows_10_1507 Windows Installer Elevation of Privilege Vulnerability | 6.3% | |
| CVE-2012-0767 | MED 6.1 | adobe flash_player Cross-site scripting (XSS) vulnerability in Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.111.6 on Android 2.x and 3.x; and before 11.1.115.6 on Android 4.x allows remote attackers to in | 6.2% | |
| CVE-2017-6627 | HIGH 7.5 | cisco ios A vulnerability in the UDP processing code of Cisco IOS 15.1, 15.2, and 15.4 and IOS XE 3.14 through 3.18 could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and a | 6.2% | |
| CVE-2019-1069 | HIGH 7.8 | ransomware microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way the Task Scheduler Service validates certain file operations. An attacker who successfully exploited the vulnerability could gain elevated privileges on a victim system. To exploit the vulnerability, an | 6.1% | |
| CVE-2021-27059 | HIGH 7.6 | microsoft office Microsoft Office Remote Code Execution Vulnerability | 6.1% | |
| CVE-2025-62215 | HIGH 7.0 | microsoft windows_10_1809 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally. | 6.0% | |
| CVE-2019-6693 | MED 6.5 | ransomware fortinet fortios Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup file to decipher the sensitive data, via knowledge of the hard-coded key. The aforementioned sensitive data incl | 5.8% | |
| CVE-2024-30051 | HIGH 7.8 | ransomware microsoft windows_10_1507 Windows DWM Core Library Elevation of Privilege Vulnerability | 5.7% | |
| CVE-2016-0167 | HIGH 7.8 | ransomware microsoft windows_10_1507 The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application | 5.7% | |
| CVE-2010-3035 | HIGH 7.5 | cisco ios_xr Cisco IOS XR 3.4.0 through 3.9.1, when BGP is enabled, does not properly handle unrecognized transitive attributes, which allows remote attackers to cause a denial of service (peering reset) via a crafted prefix announcement, as demonstrated in the wild in Aug | 5.7% | |
| CVE-2022-20700 | CRIT 10.0 | cisco rv160_firmware Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization prot | 5.7% | |
| CVE-2023-21823 | HIGH 7.8 | microsoft windows_10_1507 Windows Graphics Component Remote Code Execution Vulnerability | 5.6% | |
| CVE-2022-0492 | HIGH 7.8 | canonical ubuntu_linux A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace | 5.5% | |
| CVE-2019-15271 | HIGH 8.8 | cisco rv016_multi-wan_vpn_firmware A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker to execute arbitrary commands with root privileges. The attacker must have either a valid credential or an act | 5.5% | |
| CVE-2021-27085 | HIGH 8.8 | microsoft internet_explorer Internet Explorer Remote Code Execution Vulnerability | 5.4% | |
| CVE-2020-17087 | HIGH 7.8 | microsoft windows_10_1507 Windows Kernel Local Elevation of Privilege Vulnerability | 5.4% | |
| CVE-2017-12319 | MED 5.9 | cisco ios A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or p | 5.2% | |
| CVE-2019-0863 | HIGH 7.8 | microsoft windows_10_1507 An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. | 5.2% | |
| CVE-2015-6175 | HIGH 7.8 | microsoft windows_10_1507 The kernel in Microsoft Windows 10 Gold allows local users to gain privileges via a crafted application, aka "Windows Kernel Memory Elevation of Privilege Vulnerability." | 5.1% | |
| CVE-2021-36741 | HIGH 8.8 | trendmicro apex_one An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must firs | 5.0% | |
| CVE-2018-0180 | MED 5.9 | cisco ios Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities af | 4.9% | |
| CVE-2018-0179 | MED 5.9 | cisco ios Multiple vulnerabilities in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. These vulnerabilities af | 4.9% | |
| CVE-2025-47827 | MED 4.6 | igel igel_os In IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a crafted root filesystem can be mounted from an unverified SquashFS image. | 4.9% |