58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20094 | HIGH 8.8 | cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulne | 1.1% | — |
| CVE-2025-55243 | HIGH 7.5 | microsoft officeplus Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. | 1.1% | — |
| CVE-2025-53767 | CRIT 10.0 | microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability | 1.1% | — |
| CVE-2023-35297 | HIGH 8.1 | microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-22984 | MED 6.1 | f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafte | 1.1% | — |
| CVE-2020-16943 | MED 6.5 | microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou | 1.1% | — |
| CVE-2003-1569 | MED 5.0 | goahead goahead_webserver GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-200 | 1.1% | — |
| CVE-2026-25917 | HIGH 7.2 | apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended | 1.1% | — |
| CVE-2024-29737 | MED 4.7 | apache streampark In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to | 1.1% | — |
| CVE-2024-26220 | MED 5.0 | microsoft windows_10_1507 Windows Mobile Hotspot Information Disclosure Vulnerability | 1.1% | — |
| CVE-2024-21394 | HIGH 7.6 | microsoft dynamics_365 Dynamics 365 Field Service Spoofing Vulnerability | 1.1% | — |
| CVE-2022-21969 | CRIT 9.0 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2021-21107 | CRIT 9.6 | debian debian_linux Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | 1.1% | — |
| CVE-2020-5924 | MED 5.3 | f5 big-ip_access_policy_manager In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set. | 1.1% | — |
| CVE-2020-4636 | HIGH 7.2 | ibm resilient_security_orchestration_automation_and_response IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503. | 1.1% | — |
| CVE-2020-12876 | HIGH 7.5 | veritas aptare Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments. | 1.1% | — |
| CVE-2020-0791 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898. | 1.1% | — |
| CVE-2019-6984 | MED 6.5 | foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter a Use-After-Free or Type Confusion and crash during handling of certain PDF files that embed specifically crafted 3D content, du | 1.1% | — |
| CVE-2019-6983 | MED 6.5 | foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Integer Overflow and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of a | 1.1% | — |
| CVE-2018-0788 | HIGH 7.0 | microsoft windows_7 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka | 1.1% | — |
| CVE-2014-3295 | MED 4.8 | cisco nx-os The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309. | 1.1% | — |
| CVE-2026-50632 | HIGH 8.1 | apache cxf A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users | 1.1% | — |
| CVE-2025-24859 | HIGH 8.8 | apache roller A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing se | 1.1% | — |
| CVE-2023-5168 | CRIT 9.8 | mozilla firefox A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are | 1.1% | — |
| CVE-2023-34981 | HIGH 7.5 | apache tomcat A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (m | 1.1% | — |