58.535 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-28322 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-28313 | HIGH 7.8 | microsoft visual_studio Diagnostics Hub Standard Collector Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2021-27891 | HIGH 8.8 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. | 1.0% | — |
| CVE-2020-17092 | HIGH 7.8 | microsoft windows_10 Windows Network Connections Service Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2019-1142 | MED 5.5 | microsoft .net_framework An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'. | 1.0% | — |
| CVE-2017-9477 | MED 6.5 | cisco dpc3939_firmware The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover the CM MAC address by connecting to the de | 1.0% | — |
| CVE-2014-3180 | CRIT 9.1 | google chrome_os In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code pa | 1.0% | — |
| CVE-2013-1773 | MED 6.2 | linux linux_kernel Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly | 1.0% | — |
| CVE-2004-1335 | LOW 2.1 | linux linux_kernel Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function. | 1.0% | — |
| CVE-2026-75728 | CRIT 9.1 | adobe campaign Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this | 1.0% | — |
| CVE-2026-55976 | CRIT 9.1 | apache hive Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive server to fetch an attacker-controlled URL when resolving the avro.schema.url t | 1.0% | — |
| CVE-2026-45495 | HIGH 8.8 | microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2026-29170 | MED 6.1 | apache http_server A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to v | 1.0% | — |
| CVE-2024-28168 | HIGH 7.5 | apache formatting_objects_processor Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue. | 1.0% | — |
| CVE-2023-47539 | CRIT 9.8 | fortinet fortimail An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request. | 1.0% | — |
| CVE-2023-32672 | MED 4.3 | apache superset An Incorrect authorisation check in SQLLab in Apache Superset versions up to and including 2.1.0. This vulnerability allows an authenticated user to query tables that they do not have proper access to within Superset. The vulnerability can be exploited by leve | 1.0% | — |
| CVE-2021-22114 | MED 5.3 | vmware spring_integration_zip Addresses partial fix in CVE-2018-1263. Spring-integration-zip, versions prior to 1.0.4, exposes an arbitrary file write vulnerability, that can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z), | 1.0% | — |
| CVE-2021-22024 | HIGH 7.5 | vmware cloud_foundation The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability. An unauthenticated malicious actor with network access to the vRealize Operations Manager API can read any log file resulting in sensitive information dis | 1.0% | — |
| CVE-2015-0633 | MED 6.8 | cisco unified_computing_system The Integrated Management Controller (IMC) in Cisco Unified Computing System (UCS) 1.4(7h) and earlier on C-Series servers allows remote attackers to bypass intended access restrictions by sending crafted DHCP response packets on the local network, aka Bug ID | 1.0% | — |
| CVE-2025-62214 | MED 6.7 | microsoft visual_studio_2022 Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorized attacker to execute code locally. | 1.0% | — |
| CVE-2023-36895 | HIGH 7.8 | microsoft 365_apps Microsoft Outlook Remote Code Execution Vulnerability | 1.0% | — |
| CVE-2020-1655 | MED 5.3 | juniper junos When a device running Juniper Networks Junos OS with MPC7, MPC8, or MPC9 line cards installed and the system is configured for inline IP reassembly, used by L2TP, MAP-E, GRE, and IPIP, the packet forwarding engine (PFE) will become disabled upon receipt of lar | 1.0% | — |
| CVE-2019-6592 | CRIT 9.1 | f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.1, TMM may restart and produce a core file when validating SSL certificates in client SSL or server SSL profiles. | 1.0% | — |
| CVE-2026-78461 | HIGH 7.4 | microsoft visual_studio_code Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 1.0% | — |
| CVE-2026-70019 | MED 6.5 | microsoft windows_11_23h2 Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network. | 1.0% | — |