57.057 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.057 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-38092 | HIGH 8.8 | microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability | 1.6% | — |
| CVE-2013-5513 | HIGH 7.1 | cisco adaptive_security_appliance_software Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(7), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.7), 9.0.x before 9.0(3.3), and 9.1.x before 9.1(1.8), when the DNS ALPI eng | 1.6% | — |
| CVE-2024-21308 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2016-4467 | MED 5.9 | apache qpid_proton The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate when us | 1.6% | — |
| CVE-2017-0404 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 1.6% | — |
| CVE-2017-0403 | HIGH 7.0 | linux linux_kernel An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p | 1.6% | — |
| CVE-2015-0098 | HIGH 7.2 | microsoft windows_7 Task Scheduler in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges by triggering application execution by an invalid task, aka "Task Scheduler Elevation of Privilege Vulnerability." | 1.6% | — |
| CVE-2008-1213 | MED 4.3 | numara footprints Cross-site scripting (XSS) vulnerability in Numara FootPrints for Linux 8.1 allows remote attackers to inject arbitrary web script or HTML via the Title form field when setting an appointment. NOTE: the provenance of this information is unknown; the details a | 1.6% | — |
| CVE-2024-38260 | HIGH 8.8 | microsoft windows_server_2008 Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37340 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37339 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37338 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-37335 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26191 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2024-26186 | HIGH 8.8 | microsoft sql_2016_azure_connect_feature_pack Microsoft SQL Server Native Scoring Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2021-43075 | HIGH 8.8 | fortinet fortiwlm A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or | 1.6% | — |
| CVE-2018-4440 | MED 4.3 | apple icloud A logic issue was addressed with improved state management. This issue affected versions prior to iOS 12.1.1, Safari 12.0.2, iTunes 12.9.2 for Windows, iCloud for Windows 7.9. | 1.6% | — |
| CVE-2014-1732 | HIGH 7.5 | google chrome Use-after-free vulnerability in browser/ui/views/speech_recognition_bubble_views.cc in Google Chrome before 34.0.1847.131 on Windows and OS X and before 34.0.1847.132 on Linux allows remote attackers to cause a denial of service or possibly have unspecified ot | 1.6% | — |
| CVE-2005-0943 | MED 5.0 | cisco vpn_3000_concentrator_series_software Cisco VPN 3000 series Concentrator running firmware 4.1.7.A and earlier allows remote attackers to cause a denial of service (device reload or drop user connection) via a crafted HTTPS packet. | 1.6% | — |
| CVE-2022-41924 | CRIT 9.6 | tailscale tailscale A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows client, the local API was bound to a local TCP soc | 1.6% | — |
| CVE-2018-1355 | MED 6.1 | fortinet fortianalyzer An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attac | 1.6% | — |
| CVE-2013-1168 | HIGH 7.6 | cisco unified_meetingplace The web server in Cisco Unified MeetingPlace Application Server 7.x before 7.1MR1 Patch 2, 8.0 before 8.0MR1 Patch 1, and 8.5 before 8.5MR3 Patch 1 does not invalidate a session upon a logout action, which makes it easier for remote attackers to hijack session | 1.6% | — |
| CVE-2002-2283 | LOW 1.9 | microsoft windows_xp Microsoft Windows XP with Fast User Switching (FUS) enabled does not remove the "show processes from all users" privilege when the user is removed from the administrator group, which allows that user to view processes of other users. | 1.6% | — |
| CVE-2025-21223 | HIGH 8.8 | microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability | 1.6% | — |
| CVE-2022-20797 | MED 5.5 | cisco secure_network_analytics A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Enterprise, could allow an authenticated, remote attacker to execute arbitrary commands as an administrator on the underlying operating system. | 1.6% | — |