IT
58.543 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.543 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-37991 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0% —
CVE-2022-37988 HIGH 7.8 microsoft windows_10 Windows Kernel Elevation of Privilege Vulnerability 1.0% —
CVE-2021-22124 HIGH 7.5 fortinet fortiauthenticator An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.0 through 3.0.6; and FortiAuthenticator before 6.0.6 may allow an unauthenticated attacker to bring th 1.0% —
CVE-2018-0842 HIGH 7.0 microsoft windows_10 Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how obj 1.0% —
CVE-2018-0828 HIGH 7.8 microsoft windows_10 Windows 10 version 1607 and Windows Server 2016 allow an elevation of privilege vulnerability due to how the MultiPoint management account password is stored, aka "Windows Elevation of Privilege Vulnerability". 1.0% —
CVE-2016-9204 MED 6.5 cisco nexus_1000v_intercloud_firmware A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. K 1.0% —
CVE-2014-3291 MED 5.7 cisco wireless_lan_controller Cisco Wireless LAN Controller (WLC) devices allow remote attackers to cause a denial of service (NULL pointer dereference and device restart) via a zero value in Cisco Discovery Protocol packet data that is not properly handled during SNMP polling, aka Bug ID 1.0% —
CVE-2013-3458 HIGH 7.1 cisco adaptive_security_appliance_software Cisco Adaptive Security Appliances (ASA) devices, when SMP is used, do not properly process X.509 certificates, which allows remote attackers to cause a denial of service (device crash) via a large volume of (1) SSL or (2) TLS traffic, aka Bug ID CSCuh19462. 1.0% —
CVE-2012-0339 MED 5.0 cisco ios Cisco IOS 12.2 through 12.4 and 15.0 does not recognize the vrf-also keyword during enforcement of access-class commands, which allows remote attackers to establish TELNET connections from arbitrary source IP addresses via a standard TELNET client, aka Bug ID 1.0% —
CVE-2009-4040 MED 4.3 phpmyfaq phpmyfaq Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page. 1.0% —
CVE-2026-26121 HIGH 7.5 microsoft azure_iot_explorer Server-side request forgery (ssrf) in Azure IoT Explorer allows an unauthorized attacker to perform spoofing over a network. 1.0% —
CVE-2025-64672 HIGH 8.8 microsoft sharepoint_server Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network. 1.0% —
CVE-2024-30063 MED 6.7 microsoft windows_10_1507 Windows Distributed File System (DFS) Remote Code Execution Vulnerability 1.0% —
CVE-2021-34786 MED 6.5 cisco broadworks_commpilot_application_software Multiple vulnerabilities in Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker to delete arbitrary user accounts or gain elevated privileges on an affected system. 1.0% —
CVE-2020-3450 MED 4.9 cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative credentials to conduct SQL injection attacks on an affected system. The vulnerability is due to imp 1.0% —
CVE-2020-27126 MED 6.1 cisco webex_meetings A vulnerability in an API of Cisco Webex Meetings could allow an unauthenticated, remote attacker to conduct cross-site scripting attacks. The vulnerability is due to improper validation of user-supplied input to an application programmatic interface (API) wit 1.0% —
CVE-2020-16885 HIGH 7.8 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Storage VSP Driver improperly handles file operations. An attacker who successfully exploited this vulnerability could gain elevated privileges.</p> <p>To exploit the vulnerability, an attacker 1.0% —
CVE-2020-0957 HIGH 7.8 microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0956, CVE-2020-0958. 1.0% —
CVE-2020-0877 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0887. 1.0% —
CVE-2019-12635 MED 4.3 cisco content_security_management_appliance A vulnerability in the authorization module of Cisco Content Security Management Appliance (SMA) Software could allow an authenticated, remote attacker to gain out-of-scope access to email. The vulnerability exists because the affected software does not correc 1.0% —
CVE-2018-8170 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows kernel image handles objects in memory, aka "Windows Image Elevation of Privilege Vulnerability." This affects Windows 10, Windows 10 Servers. 1.0% —
CVE-2017-5037 HIGH 7.8 debian debian_linux An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer. 1.0% —
CVE-2017-3799 MED 5.4 cisco webex_meeting_center A vulnerability in a URL parameter of Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to perform site redirection. More Information: CSCzu78401. Known Affected Releases: T28.1. 1.0% —
CVE-2017-2636 HIGH 7.0 debian debian_linux Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline. 1.0% —
CVE-2026-21512 MED 6.5 microsoft azure_devops_server Server-side request forgery (ssrf) in Azure DevOps Server allows an authorized attacker to perform spoofing over a network. 1.0% —