57.056 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.056 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-34986 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req | 2.1% | — |
| CVE-2023-34985 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically crafted HTTP get req | 2.1% | — |
| CVE-2020-1056 | MED 5.4 | microsoft edge An elevation of privilege vulnerability exists when Microsoft Edge does not properly enforce cross-domain policies, which could allow an attacker to access information from one domain and inject it into another domain. In a web-based attack scenario, an attack | 2.1% | — |
| CVE-2017-0582 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the HTC OEM fastboot command could enable a local malicious application to execute arbitrary code within the context of the sensor hub. This issue is rated as Moderate because it first requires exploitation of separat | 2.1% | — |
| CVE-2023-28267 | MED 6.5 | microsoft remote_desktop_client Remote Desktop Protocol Client Information Disclosure Vulnerability | 2.1% | — |
| CVE-2015-0768 | MED 6.5 | cisco prime_network_control_system The Device Work Center (DWC) component in Cisco Prime Network Control System (NCS) 2.1(0.0.85), 2.2(0.0.58), and 2.2(0.0.69) does not properly implement AAA roles, which allows remote authenticated users to bypass intended access restrictions and execute comma | 2.1% | — |
| CVE-2025-27486 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2025-27485 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2025-21174 | HIGH 7.5 | microsoft windows_server_2012 Uncontrolled resource consumption in Windows Standards-Based Storage Management Service allows an unauthorized attacker to deny service over a network. | 2.1% | — |
| CVE-2022-34691 | HIGH 8.8 | microsoft windows_10 Active Directory Domain Services Elevation of Privilege Vulnerability | 2.1% | — |
| CVE-2018-0277 | HIGH 8.6 | cisco identity_services_engine A vulnerability in the Extensible Authentication Protocol-Transport Layer Security (EAP-TLS) certificate validation during EAP authentication for the Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause the ISE applicat | 2.1% | — |
| CVE-2025-61787 | HIGH 8.1 | deno deno Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a b | 2.1% | — |
| CVE-2024-20652 | HIGH 8.1 | microsoft windows_10_1507 Windows HTML Platforms Security Feature Bypass Vulnerability | 2.1% | — |
| CVE-2020-29019 | MED 5.3 | fortinet fortiweb A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to crash the httpd daemon thread by sending a request with a crafted cookie header. | 2.1% | — |
| CVE-2019-4545 | HIGH 7.5 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877. | 2.1% | — |
| CVE-2020-10863 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to trigger a shutdown via RPC from a Low Integrity process via TempShutDownMachine. | 2.1% | — |
| CVE-2020-10860 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. An Arbitrary Memory Address Overwrite vulnerability in the aswAvLog Log Library results in Denial of Service of the Avast Service (AvastSvc.exe). | 2.1% | — |
| CVE-2019-1806 | HIGH 7.7 | cisco esw2-350g52dc_firmware A vulnerability in the Simple Network Management Protocol (SNMP) input packet processor of Cisco Small Business Sx200, Sx300, Sx500, ESW2 Series Managed Switches and Small Business Sx250, Sx350, Sx550 Series Switches could allow an authenticated, remote attack | 2.1% | — |
| CVE-2017-16994 | MED 5.5 | linux linux_kernel The walk_hugetlb_range function in mm/pagewalk.c in the Linux kernel before 4.14.2 mishandles holes in hugetlb ranges, which allows local users to obtain sensitive information from uninitialized kernel memory via crafted use of the mincore() system call. | 2.1% | — |
| CVE-2013-3455 | MED 5.0 | cisco finesse Cisco Finesse allows remote attackers to obtain sensitive information by sniffing the network for HTTP query data, aka Bug ID CSCug16732. | 2.1% | — |
| CVE-2021-25238 | MED 5.3 | trendmicro officescan An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's managing port. | 2.1% | — |
| CVE-2021-25235 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file. | 2.1% | — |
| CVE-2021-25230 | MED 5.3 | trendmicro apex_one An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file. | 2.1% | — |
| CVE-2023-24937 | MED 6.5 | microsoft windows_10_1809 Windows CryptoAPI Denial of Service Vulnerability | 2.1% | — |
| CVE-2021-1706 | HIGH 7.3 | microsoft windows_10 Windows LUAFV Elevation of Privilege Vulnerability | 2.1% | — |