IT
58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.535 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2021-28322 HIGH 7.8 microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability 1.0% —
CVE-2021-28313 HIGH 7.8 microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability 1.0% —
CVE-2021-27891 HIGH 8.8 ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. 1.0% —
CVE-2020-17092 HIGH 7.8 microsoft windows_10 Windows Network Connections Service Elevation of Privilege Vulnerability 1.0% —
CVE-2019-1142 MED 5.5 microsoft .net_framework An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'. 1.0% —
CVE-2017-9477 MED 6.5 cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover the CM MAC address by connecting to the de 1.0% —
CVE-2014-3180 CRIT 9.1 google chrome_os In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code pa 1.0% —
CVE-2013-1773 MED 6.2 linux linux_kernel Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly 1.0% —
CVE-2004-1335 LOW 2.1 linux linux_kernel Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function. 1.0% —
CVE-2026-75728 CRIT 9.1 adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this 1.0% —
CVE-2026-55976 CRIT 9.1 apache hive Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url t 1.0% —
CVE-2026-45495 HIGH 8.8 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.0% —
CVE-2026-29170 MED 6.1 apache http_server A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to v 1.0% —
CVE-2024-28168 HIGH 7.5 apache formatting_objects_processor Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue. 1.0% —
CVE-2023-47539 CRIT 9.8 fortinet fortimail An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. 1.0% —
CVE-2023-32672 MED 4.3 apache superset An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leve 1.0% —
CVE-2021-22114 MED 5.3 vmware spring_integration_zip Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), 1.0% —
CVE-2021-22024 HIGH 7.5 vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information dis 1.0% —
CVE-2015-0633 MED 6.8 cisco unified_computing_system The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID 1.0% —
CVE-2025-62214 MED 6.7 microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. 1.0% —
CVE-2023-36895 HIGH 7.8 microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability 1.0% —
CVE-2020-1655 MED 5.3 juniper junos When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of lar 1.0% —
CVE-2019-6592 CRIT 9.1 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles. 1.0% —
CVE-2026-78461 HIGH 7.4 microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. 1.0% —
CVE-2026-70019 MED 6.5 microsoft windows_11_23h2 Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. 1.0% —