IT
57.380 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync

CVE Tracker

57.380 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2016-8966 MED 5.9 ibm bigfix_inventory IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle 1.2%
CVE-2016-8434 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comprom 1.2%
CVE-2016-7458 MED 5.8 vmware vsphere_client VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External En 1.2%
CVE-2010-3416 CRIT 9.8 google chrome Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. 1.2%
CVE-2004-1163 MED 5.0 cisco cns_network_registrar Cisco CNS Network Registrar Central Configuration Management (CCM) server 6.0 through 6.1.1.3 allows remote attackers to cause a denial of service (CPU consumption) by ending a connection after sending a certain sequence of packets. 1.2%
CVE-2026-40860 CRIT 9.8 apache camel JmsBinding.extractBodyFromJms() in camel-jms, and the equivalent JmsBinding class in camel-sjms, deserialized the payload of incoming JMS ObjectMessage values via javax.jms.ObjectMessage.getObject() without applying any ObjectInputFilter, class allowlist or cl 1.2%
CVE-2023-43667 HIGH 7.5 apache inlong Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.8.0, the attacker can create misleading or false log records, making it har 1.2%
CVE-2022-35753 HIGH 8.1 microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.2%
CVE-2022-35752 HIGH 8.1 microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.2%
CVE-2022-35745 HIGH 8.1 microsoft windows_10_1507 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability 1.2%
CVE-2022-20858 CRIT 9.8 cisco nexus_dashboard Multiple vulnerabilities in Cisco Nexus Dashboard could allow an unauthenticated, remote attacker to execute arbitrary commands, read or upload container image files, or perform a cross-site request forgery attack. For more information about these vulnerabilit 1.2%
CVE-2022-20758 MED 6.8 cisco ios_xr A vulnerability in the implementation of the Border Gateway Protocol (BGP) Ethernet VPN (EVPN) functionality in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to the 1.2%
CVE-2021-38642 MED 6.1 microsoft edge Microsoft Edge for iOS Spoofing Vulnerability 1.2%
CVE-2021-38641 MED 6.1 microsoft edge Microsoft Edge for Android Spoofing Vulnerability 1.2%
CVE-2019-1942 MED 4.3 cisco identity_services_engine A vulnerability in the sponsor portal web interface for Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to impact the integrity of an affected system by executing arbitrary SQL queries. The vulnerability is due to insufficien 1.2%
CVE-2019-0028 HIGH 7.5 juniper junos On Junos devices with the BGP graceful restart helper mode enabled or the BGP graceful restart mechanism enabled, a BGP session restart on a remote peer that has the graceful restart mechanism enabled may cause the local routing protocol daemon (RPD) process t 1.2%
CVE-2017-2290 HIGH 8.8 puppet mcollective-puppet-agent On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This 1.2%
CVE-2025-33051 HIGH 7.5 microsoft exchange_server Exposure of sensitive information to an unauthorized actor in Microsoft Exchange Server allows an unauthorized attacker to disclose information over a network. 1.2%
CVE-2024-43600 HIGH 7.8 microsoft office Microsoft Office Elevation of Privilege Vulnerability 1.2%
CVE-2022-22375 HIGH 7.2 ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. 1.2%
CVE-2021-31978 MED 5.5 microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability 1.2%
CVE-2020-2022 HIGH 7.5 paloaltonetworks pan-os An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. 1.2%
CVE-2020-1420 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu 1.2%
CVE-2020-1358 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Resource Policy Information Dis 1.2%
CVE-2025-20187 MED 6.5 cisco catalyst_sd-wan_manager A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to improper validation 1.2%