57.411 CVE tracked
782 Exploited now
186 Used by ransomware
Last sync
CVE Tracker
57.411 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-14686 | HIGH 7.8 | trendmicro antivirus_\+_security_2019 A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, l | 1.2% | — |
| CVE-2017-6670 | MED 6.1 | cisco unified_communications_domain_manager A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More Information: CSCvc54813. Known Affected Releases: 8 | 1.2% | — |
| CVE-2017-6604 | MED 6.1 | cisco unified_computing_system A vulnerability in the web interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability affects the following Cisco products running Cisco IMC | 1.2% | — |
| CVE-2026-26119 | HIGH 8.8 | microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2020-10866 | HIGH 7.5 | avast antivirus An issue was discovered in Avast Antivirus before 20. The aswTask RPC endpoint for the TaskEx library in the Avast Service (AvastSvc.exe) allows attackers to enumerate the network interfaces and access points from a Low Integrity process via RPC. | 1.2% | — |
| CVE-2019-12623 | MED 4.3 | cisco enterprise_network_functions_virtualization_infrastructure A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to th | 1.2% | — |
| CVE-2018-15406 | MED 6.1 | cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected system. The vu | 1.2% | — |
| CVE-2017-0328 | MED 4.7 | linux linux_kernel An information disclosure vulnerability in the NVIDIA crypto driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product | 1.2% | — |
| CVE-2013-1120 | MED 6.8 | cisco unity_express Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910. | 1.2% | — |
| CVE-2026-20921 | HIGH 7.5 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network. | 1.2% | — |
| CVE-2025-27744 | HIGH 7.8 | microsoft office Improper access control in Microsoft Office allows an authorized attacker to elevate privileges locally. | 1.2% | — |
| CVE-2022-41720 | HIGH 7.5 | golang go On Windows, restricted files can be accessed via os.DirFS and http.Dir. The os.DirFS function and http.Dir type provide access to a tree of files rooted at a given directory. These functions permit access to Windows device files under that root. For example, o | 1.2% | — |
| CVE-2002-0725 | MED 5.5 | microsoft windows_2000 NTFS file system in Windows NT 4.0 and Windows 2000 SP2 allows local attackers to hide file usage activities via a hard link to the target file, which causes the link to be recorded in the audit trail instead of the target file. | 1.2% | — |
| CVE-2021-29779 | MED 5.9 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the server performing key exchange without entity authentication on inter-host communications using man in the middle techniques. IBM X-Force ID: 203033. | 1.2% | — |
| CVE-2020-7838 | HIGH 8.8 | onstove stove A arbitrary code execution vulnerability exists in the way that the Stove client improperly validates input value. An attacker could execute arbitrary code when the user access to crafted web page. This issue affects: Smilegate STOVE Client 0.0.4.72. | 1.2% | — |
| CVE-2012-4144 | MED 4.3 | opera opera_browser Opera before 12.01 on Windows and UNIX, and before 11.66 and 12.x before 12.01 on Mac OS X, does not properly escape characters in DOM elements, which makes it easier for remote attackers to bypass cross-site scripting (XSS) protection mechanisms via a crafted | 1.2% | — |
| CVE-2026-8666 | HIGH 7.7 | rapid7 insightconnect_traceroute OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient inpu | 1.2% | — |
| CVE-2026-8665 | HIGH 7.7 | rapid7 insightconnect_translate OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient input sanitization in shell command constr | 1.2% | — |
| CVE-2026-8660 | HIGH 7.7 | rapid7 insightconnect_ping OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation when constructing shell commands. | 1.2% | — |
| CVE-2026-8592 | HIGH 7.7 | rapid7 insightconnect_awk OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe shell command construction in the processi | 1.2% | — |
| CVE-2026-32225 | HIGH 8.8 | microsoft windows_10_1607 Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | 1.2% | — |
| CVE-2024-41172 | HIGH 7.5 | apache cxf In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue to increase, eventual | 1.2% | — |
| CVE-2021-1493 | HIGH 8.5 | cisco adaptive_security_appliance_software A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a buffer overflow on an affected system. The vulnerabilit | 1.2% | — |
| CVE-2021-26892 | MED 6.2 | microsoft windows_10 Windows Extensible Firmware Interface Security Feature Bypass Vulnerability | 1.2% | — |
| CVE-2019-1692 | MED 5.3 | cisco application_policy_infrastructure_controller A vulnerability in the web-based management interface of Cisco Application Policy Infrastructure Controller (APIC) Software could allow an unauthenticated, remote attacker to access sensitive system usage information. The vulnerability is due to a lack of prop | 1.2% | — |