57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-6001 | HIGH 7.0 | linux linux_kernel Race condition in kernel/events/core.c in the Linux kernel before 4.9.7 allows local users to gain privileges via a crafted application that makes concurrent perf_event_open system calls for moving a software group into a hardware context. NOTE: this vulnerab | 1.7% | — |
| CVE-2015-2364 | HIGH 7.2 | microsoft windows_2003_server The graphics component in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privil | 1.7% | — |
| CVE-2015-2363 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.7% | — |
| CVE-2014-1733 | HIGH 7.5 | google chrome The PointerCompare function in codegen.cc in Seccomp-BPF, as used in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux, does not properly merge blocks, which might allow remote attackers to bypass intended sandbox restric | 1.7% | — |
| CVE-2013-6077 | MED 5.8 | citrix xendesktop Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions. | 1.7% | — |
| CVE-2026-0286 | HIGH 7.2 | paloaltonetworks pan-os A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticated administrator to execute arbitrary OS commands as root. The security risk posed by this issue is significantly minimized when CLI acces | 1.7% | — |
| CVE-2025-24056 | HIGH 8.8 | microsoft windows_10_1507 Heap-based buffer overflow in Windows Telephony Server allows an unauthorized attacker to execute code over a network. | 1.7% | — |
| CVE-2024-43455 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Spoofing Vulnerability | 1.7% | — |
| CVE-2023-36396 | HIGH 7.8 | microsoft windows_11_22h2 Windows Compressed Folder Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2021-22049 | CRIT 9.8 | vmware vcenter_server The vSphere Web Client (FLEX/Flash) contains an SSRF (Server Side Request Forgery) vulnerability in the vSAN Web Client (vSAN UI) plug-in. A malicious actor with network access to port 443 on vCenter Server may exploit this issue by accessing a URL request out | 1.7% | — |
| CVE-2025-26682 | HIGH 7.5 | microsoft asp.net_core Allocation of resources without limits or throttling in ASP.NET Core allows an unauthorized attacker to deny service over a network. | 1.7% | — |
| CVE-2023-23392 | CRIT 9.8 | microsoft windows_11_21h2 HTTP Protocol Stack Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2020-27786 | HIGH 7.8 | linux linux_kernel A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use c | 1.7% | — |
| CVE-2015-2552 | HIGH 7.2 | microsoft windows_10 The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 allows physically proximate attackers to bypass the Trusted Boot protection mechanism, and consequently interfere with the integrity of cod | 1.7% | — |
| CVE-2020-16945 | HIGH 8.7 | microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.7% | — |
| CVE-2020-3230 | HIGH 7.5 | cisco ios A vulnerability in the Internet Key Exchange Version 2 (IKEv2) implementation in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent IKEv2 from establishing new security associations. The vulnerability is due | 1.7% | — |
| CVE-2020-0884 | LOW 3.7 | microsoft visual_studio_2017 A spoofing vulnerability exists in Microsoft Visual Studio as it includes a reply URL that is not secured by SSL, aka 'Microsoft Visual Studio Spoofing Vulnerability'. | 1.7% | — |
| CVE-2018-15459 | MED 6.5 | cisco identity_services_engine A vulnerability in the administrative web interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to gain additional privileges on an affected device. The vulnerability is due to improper controls on certain pages in the | 1.7% | — |
| CVE-2019-0012 | HIGH 7.5 | juniper junos A Denial of Service (DoS) vulnerability in BGP in Juniper Networks Junos OS configured as a VPLS PE allows an attacker to craft a specific BGP message to cause the routing protocol daemon (rpd) process to crash and restart. While rpd restarts after a crash, re | 1.7% | — |
| CVE-2018-1307 | HIGH 8.1 | apache juddi In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data structures into UDDI data structures, there are little protections present against entity expansion and DTD ty | 1.7% | — |
| CVE-2017-4921 | HIGH 8.8 | vmware vcenter_server VMware vCenter Server (6.5 prior to 6.5 U1) contains an insecure library loading issue that occurs due to the use of LD_LIBRARY_PATH variable in an unsafe manner. Successful exploitation of this issue may allow unprivileged host users to load a shared library | 1.7% | — |
| CVE-2008-3003 | MED 6.6 | microsoft office Microsoft Office Excel 2007 Gold and SP1 does not properly delete the PWD (password) string from connections.xml when a .xlsx file is configured not to save the remote data session password, which allows local users to obtain sensitive information and obtain a | 1.7% | — |
| CVE-2025-48769 | HIGH 8.1 | apache nuttx Use After Free vulnerability was discovered in fs/vfs/fs_rename code of the Apache NuttX RTOS, that due recursive implementation and single buffer use by two different pointer variables allowed arbitrary user provided size buffer reallocation and write to the | 1.7% | — |
| CVE-2022-22489 | CRIT 9.1 | ibm mq IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM | 1.7% | — |
| CVE-2021-34739 | HIGH 8.1 | cisco cbs250-16p-2g_firmware A vulnerability in the web-based management interface of multiple Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to replay valid user session credentials and gain unauthorized access to the web-based management interface o | 1.7% | — |