IT
57.435 CVE tracked
782 Exploited now
187 Used by ransomware
Last sync

CVE Tracker

57.435 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sort descending In KEV since, sort descending
CVE-2013-1135 HIGH 7.1 cisco prime_central_for_hosted_collaboration_solution_assurance Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.0 allows remote attackers to cause a denial of service (CPU consumption and monitoring outage) via malformed TLS messages to TCP port (1) 9043 or (2) 9443, aka Bug ID CSCuc07155. 1.2%
CVE-2011-0676 HIGH 7.8 microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted applica 1.2%
CVE-2008-0324 MED 4.9 cisco vpn_client Cisco Systems VPN Client IPSec Driver (CVPNDRVA.sys) 5.0.02.0090 allows local users to cause a denial of service (crash) by calling the 0x80002038 IOCTL with a small size value, which triggers memory corruption. 1.2%
CVE-2002-2413 MED 5.0 deerfield website_pro WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name. 1.2%
CVE-2026-49181 HIGH 7.5 microsoft windows_10_1607 Integer underflow (wrap or wraparound) in Windows DHCP Client allows an unauthorized attacker to elevate privileges over a network. 1.2%
CVE-2024-21376 CRIT 9.0 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability 1.2%
CVE-2023-37581 MED 5.4 apache roller Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform an XSS attack. Mitigation: if you do not have Roller configur 1.2%
CVE-2022-25256 MED 6.1 sas web_report_studio SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page t 1.2%
CVE-2026-26125 HIGH 8.6 microsoft payment_orchestrator_service Payment Orchestrator Service Elevation of Privilege Vulnerability 1.2%
CVE-2025-26646 HIGH 8.0 microsoft .net External control of file name or path in .NET, Visual Studio, and Build Tools for Visual Studio allows an authorized attacker to perform spoofing over a network. 1.2%
CVE-2025-21417 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.2%
CVE-2024-38184 HIGH 7.8 microsoft windows_10_1607 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability 1.2%
CVE-2023-20197 HIGH 7.5 cisco secure_endpoint A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect c 1.2%
CVE-2021-0275 HIGH 8.8 juniper junos A Cross-site Scripting (XSS) vulnerability in J-Web on Juniper Networks Junos OS allows an attacker to target another user's session thereby gaining access to the users session. The other user session must be active for the attack to succeed. Once successful, 1.2%
CVE-2020-28169 HIGH 7.0 debian debian_linux The td-agent-builder plugin before 2020-12-18 for Fluentd allows attackers to gain privileges because the bin directory is writable by a user account, but a file in bin is executed as NT AUTHORITY\SYSTEM. 1.2%
CVE-2017-6611 MED 6.1 cisco prime_infrastructure A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due 1.2%
CVE-2016-6405 MED 6.5 cisco fog_director Cisco Fog Director 1.0(0) for IOx allows remote authenticated users to bypass intended access restrictions and write to arbitrary files via the Cartridge interface, aka Bug ID CSCuz89368. 1.2%
CVE-2010-2579 MED 5.0 realnetworks realplayer The cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, RealPlayer Enterprise 2.1.2, Mac RealPlayer 11.0 through 11.1, and Linux RealPlayer 11.0.2.1744 does not properly initialize the number of channels, which allows atta 1.2%
CVE-2025-50156 MED 5.7 microsoft windows_server_2008 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. 1.2%
CVE-2024-35845 CRIT 9.1 debian debian_linux In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: dbg-tlv: ensure NUL termination The iwl_fw_ini_debug_info_tlv is used as a string, so we must ensure the string is terminated correctly before using it. 1.2%
CVE-2024-0056 HIGH 8.7 microsoft .net Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability 1.2%
CVE-2023-33850 HIGH 7.5 ibm cics_tx IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulne 1.2%
CVE-2022-20891 MED 4.7 cisco rv110w_firmware Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the device to restart unexpe 1.2%
CVE-2022-34029 CRIT 9.1 f5 njs Nginx NJS v0.7.4 was discovered to contain an out-of-bounds read via njs_scope_value at njs_scope.h. 1.2%
CVE-2021-40769 LOW 3.3 adobe character_animator Adobe Character Animator version 4.4 (and earlier versions) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of 1.2%