IT
58.559 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.559 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2022-35715 HIGH 7.5 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in a stack trace. This information could be used in further attacks against the system. IBM X-Force ID: 231 1.0% —
CVE-2022-20958 HIGH 8.3 cisco broadworks_commpilot_application A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot application could allow an unauthenticated, remote attacker to perform a server-side request forgery (SSRF) attack on an affected device. This vulnerability is due to insuff 1.0% —
CVE-2021-31167 HIGH 7.8 microsoft windows_10 Windows Container Manager Service Elevation of Privilege Vulnerability 1.0% —
CVE-2021-22985 HIGH 7.5 f5 big-ip_application_security_manager On BIG-IP APM version 16.0.x before 16.0.1.1, under certain conditions, when processing VPN traffic with APM, TMM consumes excessive memory. A malicious, authenticated VPN user may abuse this to perform a DoS attack against the APM. Note: Software versions whi 1.0% —
CVE-2020-0843 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 1.0% —
CVE-2020-0842 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Installer because of the way Windows Installer handles certain filesystem operations.To exploit the vulnerability, an attacker would require unprivileged execution on the victim system, aka 'Windows Ins 1.0% —
CVE-2013-2140 LOW 3.8 linux linux_kernel The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that 1.0% —
CVE-2007-3274 MED 4.3 apple safari Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location. 1.0% —
CVE-2002-1095 MED 5.0 cisco secure_access_control_server Cisco VPN 3000 Concentrator before 2.5.2(F), with encryption enabled, allows remote attackers to cause a denial of service (reload) via a Windows-based PPTP client with the "No Encryption" option set. 1.0% —
CVE-2026-24888 MED 6.5 microsoft maker.js Maker.js is a 2D vector line drawing and shape modeling for CNC and laser cutters. In versions up to and including 0.19.1, the `makerjs.extendObject` function copies properties from source objects without proper validation, potentially exposing applications to 1.0% —
CVE-2023-51785 HIGH 7.5 apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong.This issue affects Apache InLong: from 1.7.0 through 1.9.0, the attackers can make a arbitrary file read attack using mysql driver. Users are advised to upgrade to Apache InLong's 1.10.0 or cherr 1.0% —
CVE-2023-21776 MED 5.5 microsoft windows_10 Windows Kernel Information Disclosure Vulnerability 1.0% —
CVE-2022-22310 MED 6.5 ibm websphere_application_server IBM WebSphere Application Server Liberty 21.0.0.10 through 21.0.0.12 could provide weaker than expected security. A remote attacker could exploit this weakness to obtain sensitive information and gain unauthorized access to JAX-WS applications. IBM X-Force ID: 1.0% —
CVE-2020-5406 MED 6.5 vmware tanzu_application_service_for_vms VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database usernam 1.0% —
CVE-2020-26072 HIGH 8.7 cisco iot_field_network_director A vulnerability in the SOAP API of Cisco IoT Field Network Director (FND) could allow an authenticated, remote attacker to access and modify information on devices that belong to a different domain. The vulnerability is due to insufficient authorization in the 1.0% —
CVE-2018-0390 MED 6.1 cisco webex_meetings A vulnerability in the web framework of Cisco Webex could allow an unauthenticated, remote attacker to conduct a Document Object Model-based (DOM-based) cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerab 1.0% —
CVE-2017-8577 HIGH 7.0 microsoft windows_10 Win32k in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation of privilege vulnerability when it fails to 1.0% —
CVE-2016-1394 HIGH 8.6 cisco firesight_system_software Cisco Firepower System Software 6.0.0 through 6.1.0 has a hardcoded account, which allows remote attackers to obtain CLI access by leveraging knowledge of the password, aka Bug ID CSCuz56238. 1.0% —
CVE-2026-8452 CRIT 9.8 citrix netscaler_application_delivery_controller Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server 1.0%
CVE-2026-56164 MED 5.3 microsoft sharepoint_server Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. 1.0%
CVE-2026-25185 MED 5.3 microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Shell Link Processing allows an unauthorized attacker to perform spoofing over a network. 1.0% —
CVE-2025-64676 HIGH 7.2 microsoft purview '.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network. 1.0% —
CVE-2024-43596 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.0% —
CVE-2024-43496 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability 1.0% —
CVE-2020-3244 MED 5.3 cisco staros A vulnerability in the Enhanced Charging Service (ECS) functionality of Cisco ASR 5000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to bypass the traffic classification rules on an affected device. The vulnerability is du 1.0% —