58.543 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.543 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2017-8593 | HIGH 7.0 | microsoft windows_10 Microsoft Win32k in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to | 1.0% | — |
| CVE-2011-4734 | HIGH 7.5 | parallels parallels_plesk_panel Multiple SQL injection vulnerabilities in the Control Panel in Parallels Plesk Panel 10.2.0 build 20110407.20 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by file-manager/ and certain other files. | 1.0% | — |
| CVE-2011-4725 | HIGH 7.5 | parallels parallels_plesk_panel Multiple SQL injection vulnerabilities in the Server Administration Panel in Parallels Plesk Panel 10.2.0_build1011110331.18 allow remote attackers to execute arbitrary SQL commands via crafted input to a PHP script, as demonstrated by login_up.php3 and certai | 1.0% | — |
| CVE-2026-67368 | HIGH 8.8 | microsoft sql_server_2017 Improper link resolution before file access ('link following') in SQL Server allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-63509 | CRIT 9.9 | microsoft fabric Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-59115 | CRIT 9.9 | microsoft entra_provisioning_service '.../...//' in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2026-56196 | HIGH 8.8 | microsoft windows_admin_center Relative path traversal in Windows Admin Center allows an authorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-49163 | HIGH 8.8 | microsoft application_insights_profiler Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | 1.0% | — |
| CVE-2024-35279 | HIGH 8.1 | fortinet fortios A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP cont | 1.0% | — |
| CVE-2024-27349 | CRIT 9.1 | apache hugegraph Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue. | 1.0% | — |
| CVE-2022-22026 | HIGH 8.8 | microsoft windows_10 Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability | 1.0% | — |
| CVE-2022-20808 | HIGH 7.7 | cisco smart_software_manager_on-prem A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incorrect handling of multiple simultaneous dev | 1.0% | — |
| CVE-2021-1526 | HIGH 7.8 | cisco webex_player A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in Webex Recording Format (WRF | 1.0% | — |
| CVE-2021-1511 | HIGH 7.5 | cisco vedge_1000_firmware Multiple vulnerabilities in Cisco SD-WAN vEdge Software could allow an attacker to execute arbitrary code as the root user or cause a denial of service (DoS) condition on an affected device. For more information about these vulnerabilities, see the Details sec | 1.0% | — |
| CVE-2021-1503 | HIGH 7.8 | cisco webex_meetings_server A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values i | 1.0% | — |
| CVE-2007-1861 | MED 4.9 | linux linux_kernel The nl_fib_lookup function in net/ipv4/fib_frontend.c in Linux Kernel before 2.6.20.8 allows attackers to cause a denial of service (kernel panic) via NETLINK_FIB_LOOKUP replies, which trigger infinite recursion and a stack overflow. | 1.0% | — |
| CVE-2005-3426 | MED 5.0 | cisco content_services_switch_11500 Cisco CSS 11500 Content Services Switch (CSS) with SSL termination services allows remote attackers to cause a denial of service (memory corruption and device reload) via a malformed client certificate during SSL session negotiation. | 1.0% | — |
| CVE-2022-27508 | HIGH 7.5 | citrix application_delivery_controller Unauthenticated denial of service | 1.0% | — |
| CVE-2021-22973 | HIGH 7.5 | f5 big-ip_access_policy_manager On BIG-IP version 16.0.x before 16.0.1.1, 15.1.x before 15.1.2, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all 12.1.x versions, JSON parser function does not protect against out-of-bounds memory accesses or writes. Note: Software versions which have r | 1.0% | — |
| CVE-2015-7998 | MED 5.0 | citrix netscaler_application_delivery_controller_firmware The administration UI in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allows at | 1.0% | — |
| CVE-2015-7996 | MED 5.0 | citrix netscaler_application_delivery_controller_firmware The Nitro API in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 133.9, 10.5 before Build 58.11, and 10.5.e before Build 56.1505.e on NetScaler Service Delivery Appliance Service VM (SVM) devices allow attackers t | 1.0% | — |
| CVE-2026-69845 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows DHCP Server allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-68839 | CRIT 9.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows USB Mass Storage Class Driver allows an unauthorized attacker to execute code over a network. | 1.0% | — |
| CVE-2026-50628 | CRIT 9.8 | apache cxf A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recomme | 1.0% | — |
| CVE-2023-33142 | MED 6.5 | microsoft sharepoint_server Microsoft SharePoint Server Elevation of Privilege Vulnerability | 1.0% | — |