58.518 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.518 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-27748 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.1% | — |
| CVE-2025-27745 | HIGH 7.8 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 1.1% | — |
| CVE-2022-20851 | MED 5.5 | cisco ios_xe A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this v | 1.1% | — |
| CVE-2020-0689 | MED 6.7 | microsoft windows_10 A security feature bypass vulnerability exists in secure boot, aka 'Microsoft Secure Boot Security Feature Bypass Vulnerability'. | 1.1% | — |
| CVE-2014-3342 | MED 4.0 | cisco cli The CLI in Cisco IOS XR allows remote authenticated users to obtain sensitive information via unspecified commands, aka Bug IDs CSCuq42336, CSCuq76853, CSCuq76873, and CSCuq45383. | 1.1% | — |
| CVE-2013-3425 | MED 4.0 | cisco webex The Meeting Center component in Cisco WebEx 11 generates different error messages for invalid file-access attempts depending on whether a file exists, which allows remote authenticated users to enumerate files via a series of SPI calls, aka Bug ID CSCuc35965. | 1.1% | — |
| CVE-2025-49681 | MED 6.5 | microsoft windows_server_2008 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2025-49671 | MED 6.5 | microsoft windows_server_2008 Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | 1.1% | — |
| CVE-2023-6753 | HIGH 8.8 | lfprojects mlflow Path Traversal in GitHub repository mlflow/mlflow prior to 2.9.2. | 1.1% | — |
| CVE-2023-38434 | HIGH 7.5 | xhttp_project xhttp xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method. | 1.1% | — |
| CVE-2022-47500 | MED 6.1 | apache helix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper des | 1.1% | — |
| CVE-2022-34302 | MED 6.7 | horizondatasys uefi_bootloader A flaw was found in New Horizon Datasys bootloaders before 2022-06-01. An attacker may use this bootloader to bypass or tamper with Secure Boot protections. In order to load and execute arbitrary code in the pre-boot stage, an attacker simply needs to replace | 1.1% | — |
| CVE-2022-22323 | MED 6.5 | ibm security_verify_password_synchronization IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vu | 1.1% | — |
| CVE-2022-22312 | MED 6.5 | ibm security_verify_password_synchronization IBM Security Identity Manager (IBM Security Verify Password Synchronization Plug-in for Windows AD 10.x) is vulnerable to a denial of service, caused by a heap-based buffer overflow in the Password Synch Plug-in. An authenticated attacker could exploit this vu | 1.1% | — |
| CVE-2021-22891 | CRIT 9.8 | citrix sharefile_storagezones_controller A missing authorization vulnerability exists in Citrix ShareFile Storage Zones Controller before 5.7.3, 5.8.3, 5.9.3, 5.10.1 and 5.11.18 may allow unauthenticated remote compromise of the Storage Zones Controller. | 1.1% | — |
| CVE-2021-21078 | MED 6.5 | adobe creative_cloud_desktop_application Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this iss | 1.1% | — |
| CVE-2021-1502 | HIGH 7.8 | cisco webex_meetings_desktop A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values wi | 1.1% | — |
| CVE-2021-1406 | MED 4.9 | cisco unified_communications_manager A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device. The v | 1.1% | — |
| CVE-2021-1365 | HIGH 7.1 | cisco unified_communications_manager_im_and_presence_service Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities are due | 1.1% | — |
| CVE-2021-1363 | HIGH 7.1 | cisco unified_communications_manager_im_and_presence_service Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. These vulnerabilities are due | 1.1% | — |
| CVE-2015-0659 | MED 5.0 | cisco ios The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS allows remote attackers to trigger self-referential adjacencies via a crafted Autonomic Networking (AN) message, aka Bug ID CSCup62157. | 1.1% | — |
| CVE-2012-6347 | MED 6.1 | fortinet fortidb Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext parameter to (1) admin/auditTrail.jsf, (2) | 1.1% | — |
| CVE-2001-1065 | MED 5.0 | cisco cbos Web-based configuration utility in Cisco 600 series routers running CBOS 2.0.1 through 2.4.2ap binds itself to port 80 even when web-based configuration services are disabled, which could leave the router open to attack. | 1.1% | — |
| CVE-1999-0733 | HIGH 7.2 | vmware workstation Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable. | 1.1% | — |
| CVE-2025-21393 | MED 6.3 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.1% | — |