IT
57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync

CVE Tracker

57.056 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2022-35805 HIGH 8.8 microsoft dynamics_365 Microsoft Dynamics CRM (on-premises) Remote Code Execution Vulnerability 2.5%
CVE-2024-20687 HIGH 7.5 microsoft windows_10_1507 Microsoft AllJoyn API Denial of Service Vulnerability 2.5%
CVE-2022-38023 HIGH 8.1 fedoraproject fedora Netlogon RPC Elevation of Privilege Vulnerability 2.5%
CVE-2022-30141 HIGH 8.1 microsoft windows_10 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability 2.5%
CVE-2021-39236 HIGH 8.8 apache ozone In Apache Ozone before 1.2.0, Authenticated users with valid Ozone S3 credentials can create specific OM requests, impersonating any other user. 2.5%
CVE-2019-18814 CRIT 9.8 linux linux_kernel An issue was discovered in the Linux kernel through 5.3.9. There is a use-after-free when aa_label_parse() fails in aa_audit_rule_init() in security/apparmor/audit.c. 2.5%
CVE-2018-0251 MED 6.1 cisco adaptive_security_appliance_software A vulnerability in the Web Server Authentication Required screen of the Clientless Secure Sockets Layer (SSL) VPN portal of Cisco Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) 2.5%
CVE-2018-4163 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. 2.5%
CVE-2018-4125 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. 2.5%
CVE-2018-4114 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.3 is affected. Safari before 11.1 is affected. iCloud before 7.4 on Windows is affected. iTunes before 12.7.4 on Windows is affected. tvOS before 11.3 is affected. watchOS before 4.3 is affected. 2.5%
CVE-2017-11783 HIGH 7.0 microsoft windows_10 Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability in the way it handles calls to Advanced Local Procedure Call (ALPC), aka "Windows Eleva 2.5%
CVE-2015-8104 CRIT 10.0 canonical ubuntu_linux The KVM subsystem in the Linux kernel through 4.2.6, and Xen 4.3.x through 4.6.x, allows guest OS users to cause a denial of service (host OS panic or hang) by triggering many #DB (aka Debug) exceptions, related to svm.c. 2.5%
CVE-2008-1998 HIGH 8.5 ibm db2 The NNSTAT (aka SYSPROC.NNSTAT) procedure in IBM DB2 8 before FP16, 9.1 before FP4a, and 9.5 before FP1 on Windows allows remote authenticated users to overwrite arbitrary files via the log file parameter. 2.5%
CVE-2024-38132 HIGH 7.5 microsoft windows_10_1507 Windows Network Address Translation (NAT) Denial of Service Vulnerability 2.5%
CVE-2018-13099 MED 5.5 canonical ubuntu_linux An issue was discovered in fs/f2fs/inline.c in the Linux kernel through 4.4. A denial of service (out-of-bounds memory access and BUG) can occur for a modified f2fs filesystem image in which an inline inode contains an invalid reserved blkaddr. 2.5%
CVE-2021-34450 HIGH 8.5 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 2.5%
CVE-2025-54101 MED 4.8 microsoft windows_10_1507 Use after free in Windows SMBv3 Client allows an authorized attacker to execute code over a network. 2.5%
CVE-2021-40119 CRIT 9.8 cisco policy_suite A vulnerability in the key-based SSH authentication mechanism of Cisco Policy Suite could allow an unauthenticated, remote attacker to log in to an affected system as the root user. This vulnerability is due to the re-use of static SSH keys across installation 2.5%
CVE-2020-1939 CRIT 9.8 apache nuttx The Apache NuttX (Incubating) project provides an optional separate "apps" repository which contains various optional components and example programs. One of these, ftpd, had a NULL pointer dereference bug. The NuttX RTOS itself is not affected. Users of the o 2.5%
CVE-2018-8563 MED 5.5 microsoft windows_7 An information disclosure vulnerability exists when DirectX improperly handles objects in memory, aka "DirectX Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2012, Windows 8.1, Windows Serv 2.5%
CVE-2018-8408 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly initializes objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Win 2.5%
CVE-2018-8407 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when "Kernel Remote Procedure Call Provider" driver improperly initializes objects in memory, aka "MSRPC Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windo 2.5%
CVE-2018-3962 HIGH 7.3 foxitsoftware phantompdf A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's Foxit PDF Reader version 9.1.0.5096. A use-after-free condition can occur when accessing the CreationDate property of the this.info object. An attacker needs to trick the user t 2.5%
CVE-2025-59194 HIGH 7.0 microsoft windows_11_22h2 Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.5%
CVE-2022-21221 MED 5.9 fasthttp_project fasthttp The package github.com/valyala/fasthttp before 1.34.0 are vulnerable to Directory Traversal via the ServeFile function, due to improper sanitization. It is possible to be exploited by using a backslash %5c character in the path. **Note:** This security issue i 2.5%