IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-20094 HIGH 8.8 cisco unified_computing_system A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user. This vulne 1.1% —
CVE-2025-55243 HIGH 7.5 microsoft officeplus Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network. 1.1% —
CVE-2025-53767 CRIT 10.0 microsoft azure_openai Azure OpenAI Elevation of Privilege Vulnerability 1.1% —
CVE-2023-35297 HIGH 8.1 microsoft windows_10_1507 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability 1.1% —
CVE-2021-22984 MED 6.1 f5 big-ip_advanced_web_application_firewall On BIG-IP Advanced WAF and ASM version 15.1.x before 15.1.0.2, 15.0.x before 15.0.1.4, 14.1.x before 14.1.2.5, 13.1.x before 13.1.3.4, 12.1.x before 12.1.5.2, and 11.6.x before 11.6.5.2, when receiving a unauthenticated client request with a maliciously crafte 1.1% —
CVE-2020-16943 MED 6.5 microsoft dynamics_365 <p>An elevation of privilege vulnerability exists in Microsoft Dynamics 365 Commerce. An unauthenticated attacker who successfully exploited this vulnerability could update data without proper authorization.</p> <p>To exploit the vulnerability, an attacker wou 1.1% —
CVE-2003-1569 MED 5.0 goahead goahead_webserver GoAhead WebServer before 2.1.5 on Windows 95, 98, and ME allows remote attackers to cause a denial of service (daemon crash) via an HTTP request with a (1) con, (2) nul, (3) clock$, or (4) config$ device name in a path component, different vectors than CVE-200 1.1% —
CVE-2026-25917 HIGH 7.2 apache airflow Dag Authors, who normally should not be able to execute code in the webserver context could craft XCom payload causing the webserver to execute arbitrary code. Since Dag Authors are already highly trusted, severity of this issue is Low. Users are recommended 1.1% —
CVE-2024-29737 MED 4.7 apache streampark In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is that the user needs to 1.1% —
CVE-2024-26220 MED 5.0 microsoft windows_10_1507 Windows Mobile Hotspot Information Disclosure Vulnerability 1.1% —
CVE-2024-21394 HIGH 7.6 microsoft dynamics_365 Dynamics 365 Field Service Spoofing Vulnerability 1.1% —
CVE-2022-21969 CRIT 9.0 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 1.1% —
CVE-2021-21107 CRIT 9.6 debian debian_linux Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. 1.1% —
CVE-2020-5924 MED 5.3 f5 big-ip_access_policy_manager In BIG-IP APM versions 12.1.0-12.1.5.1 and 11.6.1-11.6.5.2, RADIUS authentication leaks memory when the username for authentication is not set. 1.1% —
CVE-2020-4636 HIGH 7.2 ibm resilient_security_orchestration_automation_and_response IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503. 1.1% —
CVE-2020-12876 HIGH 7.5 veritas aptare Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulnerability only impacts Windows server deployments. 1.1% —
CVE-2020-0791 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0898. 1.1% —
CVE-2019-6984 MED 6.5 foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter a Use-After-Free or Type Confusion and crash during handling of certain PDF files that embed specifically crafted 3D content, du 1.1% —
CVE-2019-6983 MED 6.5 foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Integer Overflow and crash during the handling of certain PDF files that embed specifically crafted 3D content, because of a 1.1% —
CVE-2018-0788 HIGH 7.0 microsoft windows_7 The Windows Adobe Type Manager Font Driver (Atmfd.dll) in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, and Windows Server 2012 and R2 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka 1.1% —
CVE-2014-3295 MED 4.8 cisco nx-os The HSRP implementation in Cisco NX-OS 6.2(2a) and earlier allows remote attackers to bypass authentication and cause a denial of service (group-member state modification and traffic blackholing) via malformed HSRP packets, aka Bug ID CSCup11309. 1.1% —
CVE-2026-50632 HIGH 8.1 apache cxf A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache CXF has been identified, which can allow code execution capabilities, if untrusted users are allowed to configure JMS for Apache CXF. Users 1.1% —
CVE-2025-24859 HIGH 8.8 apache roller A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's password is changed, either by the user themselves or by an administrator, existing se 1.1% —
CVE-2023-5168 CRIT 9.8 mozilla firefox A compromised content process could have provided malicious data to `FilterNodeD2D1` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. *This bug only affects Firefox on Windows. Other operating systems are 1.1% —
CVE-2023-34981 HIGH 7.5 apache tomcat A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (m 1.1% —