IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted ascending In KEV since, sort descending
CVE-2020-12657 HIGH 7.8 linux linux_kernel An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body. 0.7% —
CVE-2020-1002 HIGH 7.1 microsoft forefront_endpoint_protection_2010 An elevation of privilege vulnerability exists when the MpSigStub.exe for Defender allows file deletion in arbitrary locations.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Microsoft Defender Elevation of Privilege Vu 0.7% —
CVE-2014-0737 MED 4.3 cisco unified_ip_phone_7960g The Cisco Unified IP Phone 7960G 9.2(1) and earlier allows remote attackers to bypass authentication and change trust relationships by injecting a Certificate Trust List (CTL) file, aka Bug ID CSCuj66795. 0.7% —
CVE-2010-3849 MED 4.7 canonical ubuntu_linux The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value 0.7% —
CVE-2026-20034 HIGH 8.8 cisco unity_connection A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An at 0.7% —
CVE-2025-64675 HIGH 8.3 microsoft azure_cosmos_db Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network. 0.7% —
CVE-2025-53787 HIGH 8.2 microsoft 365_copilot_chat Microsoft 365 Copilot BizChat Information Disclosure Vulnerability 0.7% —
CVE-2025-48431 HIGH 7.5 apache thrift Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted request 0.7% —
CVE-2025-20343 HIGH 8.6 cisco identity_services_engine A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco ISE to restart unexpectedly. This vulnerability is due to 0.7% —
CVE-2024-35261 HIGH 7.8 microsoft azure_network_watcher_agent Azure Network Watcher VM Extension Elevation of Privilege Vulnerability 0.7% —
CVE-2024-24859 MED 4.6 linux linux_kernel A race condition was found in the Linux kernel's net/bluetooth in sniff_{min,max}_interval_set() function. This can result in a bluetooth sniffing exception issue, possibly leading denial of service. 0.7% —
CVE-2023-33857 MED 5.3 ibm infosphere_information_server IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain system information using a specially crafted query that could aid in further attacks against the system. IBM X-Force ID: 257695. 0.7% —
CVE-2023-29413 HIGH 7.5 schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause Denial-of-Service when accessed by an unauthenticated user on the Schneider UPS Monitor service. 0.7% —
CVE-2023-21750 HIGH 7.1 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.7% —
CVE-2023-20190 MED 5.8 cisco ios_xr A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by a configured ACL on an affected device. This vulnerability is d 0.7% —
CVE-2022-43908 MED 4.3 ibm security_guardium IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM X-Force ID: 240903. 0.7% —
CVE-2022-43903 MED 4.3 ibm security_guardium IBM Security Guardium 10.6, 11.3, and 11.4 could allow an authenticated user to cause a denial of service due to due to improper input validation. IBM X-Force ID: 240894. 0.7% —
CVE-2022-42970 CRIT 9.8 schneider-electric apc_easy_ups_online_monitoring_software A CWE-306: Missing Authentication for Critical Function The software does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. Affected Products: APC Easy UPS Online Monitoring S 0.7% —
CVE-2022-38032 MED 6.6 microsoft windows_10 Windows Portable Device Enumerator Service Security Feature Bypass Vulnerability 0.7% —
CVE-2022-34335 MED 6.5 ibm sterling_partner_engagement_manager IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705. 0.7% —
CVE-2022-33682 MED 5.9 apache pulsar TLS hostname verification cannot be enabled in the Pulsar Broker's Java Client, the Pulsar Broker's Java Admin Client, the Pulsar WebSocket Proxy's Java Client, and the Pulsar Proxy's Admin Client leaving intra-cluster connections and geo-replication connectio 0.7% —
CVE-2021-1382 MED 6.0 cisco ios_xe A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system. This vulnerability is due to insufficient input validat 0.7% —
CVE-2020-16900 HIGH 7.0 microsoft windows_10 <p>An elevation of privilege vulnerability exists when the Windows Event System improperly handles objects in memory.</p> <p>To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specia 0.7% —
CVE-2019-1695 MED 6.5 cisco adaptive_security_appliance_software A vulnerability in the detection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to send data directly to the kernel of an affected device. The vulne 0.7% —
CVE-2019-15221 MED 4.6 canonical ubuntu_linux An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver. 0.7% —