58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.507 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-1524 | MED 4.3 | cisco meeting_server A vulnerability in the API of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because requests that are sent to the API are not properly validated. | 1.1% | — |
| CVE-2021-0210 | MED 6.8 | juniper junos An Information Exposure vulnerability in J-Web of Juniper Networks Junos OS allows an unauthenticated attacker to elevate their privileges over the target system through opportunistic use of an authenticated users session. This issue affects: Juniper Networks | 1.1% | — |
| CVE-2020-36405 | HIGH 7.8 | keystone-engine keystone_engine Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken. | 1.1% | — |
| CVE-2019-1851 | MED 6.8 | cisco identity_services_engine A vulnerability in the External RESTful Services (ERS) API of the Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to generate arbitrary certificates signed by the Internal Certificate Authority (CA) Services on ISE. This vuln | 1.1% | — |
| CVE-2019-0017 | MED 6.5 | juniper junos_space The Junos Space application, which allows Device Image files to be uploaded, has insufficient validity checking which may allow uploading of malicious images or scripts, or other content types. Affected releases are Juniper Networks Junos Space versions prior | 1.1% | — |
| CVE-2004-0244 | MED 4.7 | cisco ios Cisco 6000, 6500, and 7600 series systems with Multilayer Switch Feature Card 2 (MSFC2) and a FlexWAN or OSM module allow local users to cause a denial of service (hang or reset) by sending a layer 2 frame packet that encapsulates a layer 3 packet, but has inc | 1.1% | — |
| CVE-1999-0159 | LOW 3.5 | cisco ios Attackers can crash a Cisco IOS router or device, provided they can get to an interactive prompt (such as a login). This applies to some IOS 9.x, 10.x, and 11.x releases. | 1.1% | — |
| CVE-2026-20922 | HIGH 7.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows NTFS allows an authorized attacker to execute code locally. | 1.1% | — |
| CVE-2026-20854 | HIGH 7.5 | microsoft windows_11_24h2 Use after free in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2022-24511 | MED 5.5 | microsoft 365_apps Microsoft Office Word Tampering Vulnerability | 1.1% | — |
| CVE-2022-20823 | HIGH 8.6 | cisco nexus_3016_firmware A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of speci | 1.1% | — |
| CVE-2022-20733 | MED 5.3 | cisco identity_services_engine A vulnerability in the login page of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to log in without credentials and access all roles without any restrictions. This vulnerability is due to exposed sensitive Security Asser | 1.1% | — |
| CVE-2021-40130 | MED 4.9 | cisco common_services_platform_collector A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could allow an authenticated, remote attacker to specify non-log files as sources for syslog reporting. This vulnerability is due to improper restriction of the syslog co | 1.1% | — |
| CVE-2021-36168 | MED 6.5 | fortinet fortiportal A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5.3.6 and any FortiPortal before 6.2.5 allows authenticated attacker to disclosure information via crafted GET r | 1.1% | — |
| CVE-2021-22044 | HIGH 7.5 | vmware spring_cloud_openfeign In Spring Cloud OpenFeign 3.0.0 to 3.0.4, 2.2.0.RELEASE to 2.2.9.RELEASE, and older unsupported versions, applications using type-level `@RequestMapping`annotations over Feign client interfaces, can be involuntarily exposing endpoints corresponding to `@Reques | 1.1% | — |
| CVE-2020-28588 | MED 5.5 | linux linux_kernel An information disclosure vulnerability exists in the /proc/pid/syscall functionality of Linux Kernel 5.1 Stable and 5.4.66. More specifically, this issue has been introduced in v5.1-rc4 (commit 631b7abacd02b88f4b0795c08b54ad4fc3e7c7c0) and is still present in | 1.1% | — |
| CVE-2019-1167 | MED 4.1 | microsoft powershell_core A security feature bypass vulnerability exists in Windows Defender Application Control (WDAC) which could allow an attacker to bypass WDAC enforcement, aka 'Windows Defender Application Control Security Feature Bypass Vulnerability'. | 1.1% | — |
| CVE-2007-1000 | HIGH 7.2 | linux linux_kernel The ipv6_getsockopt_sticky function in net/ipv6/ipv6_sockglue.c in the Linux kernel before 2.6.20.2 allows local users to read arbitrary kernel memory via certain getsockopt calls that trigger a NULL dereference. | 1.1% | — |
| CVE-2026-66312 | MED 6.5 | microsoft edge_chromium Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. | 1.1% | — |
| CVE-2025-21366 | HIGH 7.8 | microsoft 365_apps Microsoft Access Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2023-21783 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2022-44676 | HIGH 8.1 | microsoft windows_10 Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability | 1.1% | — |
| CVE-2019-1278 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists in the way that the unistore.dll handles objects in memory, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1215, CVE-2019-1253, CVE-2019-1303. | 1.1% | — |
| CVE-2018-15387 | CRIT 9.8 | cisco sd-wan A vulnerability in the Cisco SD-WAN Solution could allow an unauthenticated, remote attacker to bypass certificate validation on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by su | 1.1% | — |
| CVE-2017-3833 | MED 6.1 | cisco unified_communications_manager A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb959 | 1.1% | — |