IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2019-1828 MED 5.9 cisco rv320_firmware A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an unauthenticated, remote attacker to access administrative credentials. The vulnerability exists because affected devices u 0.7% —
CVE-2019-16784 HIGH 7.0 pyinstaller pyinstaller In PyInstaller before version 3.6, only on Windows, a local privilege escalation vulnerability is present in this particular case: If a software using PyInstaller in "onefile" mode is launched by a privileged user (at least more than the current one) which hav 0.7% —
CVE-2026-45860 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conncount: increase the connection clean up limit to 64 After the optimization to only perform one GC per jiffy, a new problem was introduced. If more than 8 new connections ar 0.7% —
CVE-2026-31379 MED 6.1 apache ofbiz Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This 0.7% —
CVE-2024-38078 HIGH 7.5 microsoft windows_11_21h2 Xbox Wireless Adapter Remote Code Execution Vulnerability 0.7% —
CVE-2023-21738 HIGH 7.8 microsoft 365_apps Microsoft Office Visio Remote Code Execution Vulnerability 0.7% —
CVE-2022-26240 MED 6.5 beckmancoulter remisol_advance The default privileges for the running service Normand Message Buffer in Beckman Coulter Remisol Advance v2.0.12.1 and prior allows non-privileged users to overwrite and manipulate executables and libraries. This allows attackers to access sensitive data. 0.7% —
CVE-2021-1690 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1689 HIGH 7.8 microsoft windows_10 Windows Multipoint Management Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1688 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1687 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1686 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1681 HIGH 7.8 microsoft windows_10 Windows WalletService Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1662 HIGH 7.8 microsoft windows_10 Windows Event Tracing Elevation of Privilege Vulnerability 0.7% —
CVE-2021-1659 HIGH 7.8 microsoft windows_10 Windows CSC Service Elevation of Privilege Vulnerability 0.7% —
CVE-2018-1353 MED 4.3 fortinet fortimanager An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom. 0.7% —
CVE-2015-7363 MED 5.4 fortinet fortianalyzer_firmware Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrato 0.7% —
CVE-2026-45583 HIGH 7.5 microsoft exchange_server Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network. 0.7% —
CVE-2025-47158 CRIT 9.0 microsoft azure_devops Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network. 0.7% —
CVE-2024-49052 HIGH 8.2 microsoft azure_functions Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. 0.7% —
CVE-2024-29981 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.7% —
CVE-2024-26954 HIGH 8.1 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix slab-out-of-bounds in smb_strndup_from_utf16() If ->NameOffset of smb2_create_req is smaller than Buffer offset of smb2_create_req, slab-out-of-bounds read can happen from smb2_op 0.7% —
CVE-2023-38734 MED 6.6 ibm robotic_process_automation IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable to incorrect privilege assignment when importing users from an LDAP directory. IBM X-Force ID: 262481. 0.7% —
CVE-2022-37971 HIGH 7.1 microsoft malware_protection_engine Microsoft Windows Defender Elevation of Privilege Vulnerability 0.7% —
CVE-2022-3566 MED 4.6 linux linux_kernel A vulnerability was identified in Linux Kernel up to 4.19.316/5.4.278/5.10.220/5.15.161. This impacts the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. Such manipulation leads to race condition. A high complexity level is associated with 0.7% —