IT
58.639 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.639 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2019-0984 HIGH 7.0 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Common Log File System (CLFS) driver improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run processes in an elevated context. To exploit the vuln 0.9% —
CVE-2019-0960 HIGH 7.0 microsoft windows_7 An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install pr 0.9% —
CVE-2017-3005 HIGH 7.8 adobe photoshop_cc Adobe Photoshop versions CC 2017 (18.0.1) and earlier, CC 2015.5.1 (17.0.1) and earlier have an unquoted search path vulnerability. 0.9% —
CVE-2013-1199 MED 4.9 cisco adaptive_security_appliance Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources withi 0.9% —
CVE-2024-33868 CRIT 9.8 linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is LDAP injection. 0.9% —
CVE-2024-21382 MED 4.3 microsoft edge_chromium Microsoft Edge for Android Information Disclosure Vulnerability 0.9% —
CVE-2023-20010 HIGH 8.1 cisco unified_communications_manager A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injecti 0.9% —
CVE-2022-0030 HIGH 8.1 paloaltonetworks pan-os An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows a network-based attacker with specific knowledge of the target firewall or Panorama appliance to impersonate an existing PAN-OS administrator and perform privilege 0.9% —
CVE-2021-26619 HIGH 7.1 bigfile bigfileagent An path traversal vulnerability leading to delete arbitrary files was discovered in BigFileAgent. Remote attackers can use this vulnerability to delete arbitrary files of unspecified number of users. 0.9% —
CVE-2019-1577 MED 6.3 paloaltonetworks traps Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML. 0.9% —
CVE-2017-4930 MED 5.4 vmware airwatch VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user being red 0.9% —
CVE-2016-9250 HIGH 7.5 f5 big-ip_access_policy_manager In F5 BIG-IP 11.2.1, 11.4.0 through 11.6.1, and 12.0.0 through 12.1.2, an unauthenticated user with access to the control plane may be able to delete arbitrary files through an undisclosed mechanism. 0.9% —
CVE-2015-0568 HIGH 7.8 linux linux_kernel Use-after-free vulnerability in the msm_set_crop function in drivers/media/video/msm/msm_camera.c in the MSM-Camera driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows a 0.9% —
CVE-2010-4183 MED 4.3 htmlpurifier htmlpurifier Multiple cross-site scripting (XSS) vulnerabilities in HTML Purifier before 4.1.0, when Internet Explorer is used, allow remote attackers to inject arbitrary web script or HTML via a crafted (1) background-image, (2) background, or (3) font-family Cascading St 0.9% —
CVE-2026-73025 CRIT 9.8 microsoft windows_10_1607 Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network. 0.9% —
CVE-2026-69843 CRIT 10.0 microsoft fabric Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-66803 CRIT 10.0 microsoft azure_cosmos_db Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. 0.9% —
CVE-2026-65801 CRIT 10.0 microsoft exchange_online Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-57106 CRIT 10.0 microsoft purview_data_governance Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-56191 CRIT 10.0 microsoft exchange_online Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network. 0.9% —
CVE-2026-56163 CRIT 10.0 microsoft azure_kubernetes_service Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-56162 CRIT 10.0 microsoft azure_sql_database Improper authentication in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-47280 CRIT 10.0 microsoft azure_resource_manager Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-45480 CRIT 10.0 microsoft azure_active_directory Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. 0.9% —
CVE-2026-42822 CRIT 10.0 microsoft azure_local Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network. 0.9% —