57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-24859 | HIGH 7.5 | microsoft windows_10 Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-21813 | HIGH 7.5 | microsoft windows_10 Windows Secure Channel Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-21811 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Service Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-21702 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Service Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-21701 | HIGH 7.5 | microsoft windows_10 Microsoft Protected Extensible Authentication Protocol (PEAP) Denial of Service Vulnerability | 1.7% | — |
| CVE-2023-21700 | HIGH 7.5 | microsoft windows_10 Windows iSCSI Discovery Service Denial of Service Vulnerability | 1.7% | — |
| CVE-2020-1443 | MED 5.4 | microsoft sharepoint_enterprise_server A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. | 1.7% | — |
| CVE-2019-1211 | HIGH 7.3 | microsoft visual_studio_2017 An elevation of privilege vulnerability exists in Git for Visual Studio when it improperly parses configuration files. An attacker who successfully exploited the vulnerability could execute code in the context of another local user. To exploit the vulnerabilit | 1.7% | — |
| CVE-2018-0290 | MED 5.3 | cisco socialminer A vulnerability in the TCP stack of Cisco SocialMiner could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the notification system. The vulnerability is due to faulty handling of new TCP connections to the affected ap | 1.7% | — |
| CVE-2016-8807 | HIGH 7.8 | nvidia gpu_driver For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 375.63 contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgDdiEscape ID 0x10000e9 where a value is passed from an | 1.7% | — |
| CVE-2013-3865 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.7% | — |
| CVE-2013-3864 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.7% | — |
| CVE-2013-1344 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.7% | — |
| CVE-2013-1343 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a | 1.7% | — |
| CVE-1999-0162 | MED 5.0 | cisco ios The "established" keyword in some Cisco IOS software allowed an attacker to bypass filtering. | 1.7% | — |
| CVE-2017-8530 | MED 5.4 | microsoft edge Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to trick a user into loading a page with malicious content when Microsoft Edge does not properly enforce same-origin policies, aka "Microsoft Edge Sec | 1.7% | — |
| CVE-2015-2428 | LOW 2.1 | microsoft windows_7 Object Manager in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly constrain impersonation levels during interaction with obje | 1.7% | — |
| CVE-1999-0546 | MED 4.6 | microsoft windows_nt The Windows NT guest account is enabled. | 1.7% | — |
| CVE-2024-21375 | HIGH 8.8 | microsoft windows_10_1507 Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2019-0778 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft Office SharePoint XSS Vulnerability'. | 1.7% | — |
| CVE-2017-5107 | MED 5.3 | google chrome A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and Mac allowed a remote attacker to extract pixel values from a cross-origin page being iframe'd via a crafted HTML page. | 1.7% | — |
| CVE-2014-3286 | MED 5.0 | cisco webex_meetings_server The web framework in Cisco WebEx Meeting Server does not properly restrict the content of reply messages, which allows remote attackers to obtain sensitive information via a crafted URL, aka Bug IDs CSCuj81685, CSCuj81688, CSCuj81665, CSCuj81744, and CSCuj8166 | 1.7% | — |
| CVE-2014-2199 | MED 5.0 | cisco webex_business_suite meetinginfo.do in Cisco WebEx Event Center, WebEx Meeting Center, WebEx Sales Center, WebEx Training Center, WebEx Meetings Server 1.5(.1.131) and earlier, and WebEx Business Suite (WBS) 27 before 27.32.31.16, 28 before 28.12.13.18, and 29 before 29.5.1.12 all | 1.7% | — |
| CVE-2012-4085 | MED 5.0 | cisco unified_computing_system The Intelligent Platform Management Interface (IPMI) implementation in the Blade Management Controller in Cisco Unified Computing System (UCS) allows remote attackers to enumerate valid usernames by observing IPMI interface responses, aka Bug ID CSCtg20761. | 1.7% | — |
| CVE-2024-49068 | HIGH 8.2 | microsoft sharepoint_server Microsoft SharePoint Elevation of Privilege Vulnerability | 1.7% | — |