IT
57.298 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.298 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2023-41770 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41769 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41768 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41767 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-41765 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-38166 HIGH 8.1 microsoft windows_10_1507 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability 1.3%
CVE-2023-23400 HIGH 7.2 microsoft windows_server_2012 Windows DNS Server Remote Code Execution Vulnerability 1.3%
CVE-2022-42466 MED 6.1 apache isis Prior to 2.0.0-M9, it was possible for an end-user to set the value of an editable string property of a domain object to a value that would be rendered unchanged when the value was saved. In particular, the end-user could enter javascript or similar and this w 1.3%
CVE-2016-1322 HIGH 7.5 cisco spark The REST interface in Cisco Spark 2015-07-04 allows remote attackers to bypass intended access restrictions and create arbitrary user accounts via unspecified web requests, aka Bug ID CSCuv72584. 1.3%
CVE-2016-1299 MED 5.3 cisco 300_series_managed_switch_firmware The web-management GUI implementation on Cisco Small Business SG300 devices 1.4.1.x allows remote attackers to cause a denial of service (HTTPS outage) via crafted HTTPS requests, aka Bug ID CSCuw87174. 1.3%
CVE-2011-2731 MED 5.1 vmware springsource_spring_security Race condition in the RunAsManager mechanism in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 stores the Authentication object in the shared security context, which allows attackers to gain privileges via a crafted thread. 1.3%
CVE-2023-20900 HIGH 7.1 debian debian_linux A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that targe 1.3%
CVE-2021-43220 LOW 3.1 microsoft edge_ios Microsoft Edge for iOS Spoofing Vulnerability 1.3%
CVE-2021-42308 LOW 3.1 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.3%
CVE-2018-0149 MED 4.8 cisco integrated_management_controller_supervisor A vulnerability in the web-based management interface of Cisco Integrated Management Controller Supervisor Software and Cisco UCS Director Software could allow an authenticated, remote attacker to conduct a Document Object Model-based (DOM-based), stored cross 1.3%
CVE-2014-2146 MED 6.5 cisco ios The Zone-Based Firewall (ZBFW) functionality in Cisco IOS, possibly 15.4 and earlier, and IOS XE, possibly 3.13 and earlier, mishandles zone checking for existing sessions, which allows remote attackers to bypass intended resource-access restrictions via spoof 1.3%
CVE-2009-1337 MED 4.4 linux linux_kernel The exit_notify function in kernel/exit.c in the Linux kernel before 2.6.30-rc1 does not restrict exit signals when the CAP_KILL capability is held, which allows local users to send an arbitrary signal to a process by running a program that modifies the exit_s 1.3%
CVE-2026-50517 CRIT 9.9 microsoft 365_copilot Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network. 1.3%
CVE-2022-43720 MED 5.4 apache superset An authenticated attacker with write CSS template permissions can create a record with specific HTML tags that will not get properly escaped by the toast message displayed when a user deletes that specific CSS template record. This issue affects Apache Superse 1.3%
CVE-2021-1672 MED 5.5 microsoft windows_10 Windows Projected File System FS Filter Driver Information Disclosure Vulnerability 1.3%
CVE-2020-3585 MED 5.3 cisco adaptive_security_appliance_software A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain access to sensitive infor 1.3%
CVE-2019-0965 HIGH 7.6 microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a 1.3%
CVE-2017-7053 HIGH 7.8 apple itunes An issue was discovered in certain Apple products. iTunes before 12.6.2 on Windows is affected. The issue involves the "iTunes" component. It allows attackers to execute arbitrary code in a privileged context via a crafted app. 1.3%
CVE-2016-8415 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. 1.3%
CVE-2016-8412 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the Qualcomm camera could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ 1.3%