57.075 CVE tracked
777 Exploited now
184 Used by ransomware
Last sync
CVE Tracker
57.075 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-46365 | CRIT 9.1 | apache streampark Apache StreamPark 1.0.0 before 2.0.0 When the user successfully logs in, to modify his profile, the username will be passed to the server-layer as a parameter, but not verified whether the user name is the currently logged user and whether the user is legal, T | 1.5% | — |
| CVE-2023-27296 | HIGH 8.8 | apache inlong Deserialization of Untrusted Data vulnerability in Apache Software Foundation Apache InLong. It could be triggered by authenticated users of InLong, you could refer to [1] to know more about this vulnerability. This issue affects Apache InLong: from 1.1.0 th | 1.5% | — |
| CVE-2022-41048 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-41047 | HIGH 8.8 | microsoft windows_10 Microsoft ODBC Driver Remote Code Execution Vulnerability | 1.5% | — |
| CVE-2022-37978 | HIGH 7.5 | microsoft windows_10 Windows Active Directory Certificate Services Security Feature Bypass | 1.5% | — |
| CVE-2021-29907 | HIGH 8.8 | ibm openpages_with_watson IBM OpenPages with Watson 8.1 and 8.2 could allow an authenticated user to upload a file that could execute arbitrary code on the system. IBM X-Force ID: 207633. | 1.5% | — |
| CVE-2021-36007 | LOW 3.3 | adobe prelude Adobe Prelude version 10.0 (and earlier) are affected by an uninitialized variable vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose arbitrary memory information in the context of the | 1.5% | — |
| CVE-2021-21999 | HIGH 7.8 | vmware app_volumes VMware Tools for Windows (11.x.y prior to 11.2.6), VMware Remote Console for Windows (12.x prior to 12.0.1) , VMware App Volumes (2.x prior to 2.18.10 and 4 prior to 2103) contain a local privilege escalation vulnerability. An attacker with normal access to a | 1.5% | — |
| CVE-2020-1049 | MED 5.4 | microsoft dynamics_365_server A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. This | 1.5% | — |
| CVE-2020-0754 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0753. | 1.5% | — |
| CVE-2020-0656 | MED 5.4 | microsoft dynamics_365 A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server, aka 'Microsoft Dynamics 365 (On-Premise) Cross Site Scripting Vulnerability'. | 1.5% | — |
| CVE-2025-21332 | MED 4.3 | microsoft windows_10_1507 MapUrlToZone Security Feature Bypass Vulnerability | 1.5% | — |
| CVE-2023-28742 | HIGH 7.2 | f5 big-ip_domain_name_system When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1.5% | — |
| CVE-2022-27489 | HIGH 7.2 | fortinet fortiextender_firmware A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.2.4 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests. | 1.5% | — |
| CVE-2017-5099 | HIGH 8.8 | debian debian_linux Insufficient validation of untrusted input in PPAPI Plugins in Google Chrome prior to 60.0.3112.78 for Mac allowed a remote attacker to potentially gain privilege elevation via a crafted HTML page. | 1.5% | — |
| CVE-2024-20352 | MED 4.9 | cisco emergency_responder A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient pro | 1.5% | — |
| CVE-2023-32200 | HIGH 8.8 | apache jena There is insufficient restrictions of called script functions in Apache Jena versions 4.8.0 and earlier. It allows a remote user to execute javascript via a SPARQL query. This issue affects Apache Jena: from 3.7.0 through 4.8.0. | 1.5% | — |
| CVE-2019-6590 | MED 5.9 | f5 big-ip_local_traffic_manager On BIG-IP LTM 13.0.0 to 13.0.1 and 12.1.0 to 12.1.3.6, under certain conditions, the TMM may consume excessive resources when processing SSL Session ID Persistence traffic. | 1.5% | — |
| CVE-2017-3885 | MED 5.9 | cisco secure_firewall_management_center A vulnerability in the detection engine reassembly of Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process consumes a high | 1.5% | — |
| CVE-2025-26635 | MED 6.5 | microsoft windows_10_1809 Weak authentication in Windows Hello allows an authorized attacker to bypass a security feature over a network. | 1.5% | — |
| CVE-2022-24963 | CRIT 9.8 | apache portable_runtime Integer Overflow or Wraparound vulnerability in apr_encode functions of Apache Portable Runtime (APR) allows an attacker to write beyond bounds of a buffer. This issue affects Apache Portable Runtime (APR) version 1.7.0. | 1.5% | — |
| CVE-2021-36166 | CRIT 9.8 | fortinet fortimail An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication token by means of the observation of certain system's properties. | 1.5% | — |
| CVE-2018-0404 | HIGH 7.5 | cisco rv180w_wireless-n_multifunction_vpn_router A vulnerability in the web framework code for Cisco RV180W Wireless-N Multifunction VPN Router and Small Business RV Series RV220W Wireless Network Security Firewall could allow an unauthenticated, remote attacker to execute arbitrary SQL queries. The attacker | 1.5% | — |
| CVE-2016-9677 | MED 5.3 | citrix provisioning_services Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified vectors. | 1.5% | — |
| CVE-2024-27905 | CRIT 9.1 | apache aurora ** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora. An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a | 1.5% | — |