IT
58.645 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.645 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-49073 MED 6.8 microsoft windows_10_1809 Windows Mobile Broadband Driver Elevation of Privilege Vulnerability 0.9% —
CVE-2024-38152 HIGH 7.8 microsoft windows_10_1507 Windows OLE Remote Code Execution Vulnerability 0.9% —
CVE-2023-37935 MED 6.5 fortinet fortios A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker to view plaintext passwords of remote services such as RDP or VNC, if the attacker is able to read the GET req 0.9% —
CVE-2023-3312 HIGH 7.5 linux linux_kernel A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service. 0.9% —
CVE-2022-31689 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token. 0.9% —
CVE-2022-31687 CRIT 9.8 vmware workspace_one_assist VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. 0.9% —
CVE-2022-20925 MED 6.3 cisco secure_firewall_management_center A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient 0.9% —
CVE-2021-36938 MED 5.5 microsoft windows_10 Windows Cryptographic Primitives Library Information Disclosure Vulnerability 0.9% —
CVE-2020-17088 HIGH 7.8 microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability 0.9% —
CVE-2020-11582 HIGH 8.8 pulsesecure pulse_connect_secure An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a rando 0.9% —
CVE-2015-1305 MED 6.9 mcafee data_loss_prevention_endpoint McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call. 0.9% —
CVE-2024-37978 HIGH 8.0 microsoft windows_11_22h2 Secure Boot Security Feature Bypass Vulnerability 0.9% —
CVE-2023-29338 MED 6.6 microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability 0.9% —
CVE-2022-35779 HIGH 7.8 microsoft azure_real_time_operating_system_guix_studio Azure RTOS GUIX Studio Remote Code Execution Vulnerability 0.9% —
CVE-2021-39006 MED 5.3 ibm qradar_wincollect IBM QRadar WinCollect Agent 10.0 and 10.0.1 could allow an attacker to obtain sensitive information due to missing best practices. IBM X-Force ID: 213549. 0.9% —
CVE-2019-6618 MED 4.9 f5 big-ip_access_policy_manager On BIG-IP 14.0.0-14.1.0.1, 13.0.0-13.1.1.4, 12.1.0-12.1.4, 11.6.1-11.6.3.4, and 11.5.2-11.5.8, users with the Resource Administrator role can modify sensitive portions of the filesystem if provided Advanced Shell Access, such as editing /etc/passwd. This allow 0.9% —
CVE-2019-25049 HIGH 7.1 openbsd libressl LibreSSL 2.9.1 through 3.2.1 has an out-of-bounds read in asn1_item_print_ctx (called from asn1_template_print_ctx). 0.9% —
CVE-2019-25048 HIGH 7.1 openbsd libressl LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print). 0.9% —
CVE-2019-1875 MED 4.8 cisco prime_service_catalog A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficien 0.9% —
CVE-2019-1162 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC). An attacker who successfully exploited this vulnerability could run arbitrary code in the security context of the local system. An att 0.9% —
CVE-2023-28238 HIGH 7.5 microsoft windows_10_1507 Windows Internet Key Exchange (IKE) Protocol Extensions Remote Code Execution Vulnerability 0.9% —
CVE-2023-20187 HIGH 8.6 cisco ios_xe A vulnerability in the Multicast Leaf Recycle Elimination (mLRE) feature of Cisco IOS XE Software for Cisco ASR 1000 Series Aggregation Services Routers could allow an unauthenticated, remote attacker to cause the affected device to reload, resulting in a deni 0.9% —
CVE-2021-1731 MED 5.5 microsoft windows_10 PFX Encryption Security Feature Bypass Vulnerability 0.9% —
CVE-2017-8044 MED 6.1 vmware single_sign-on_for_pivotal_cloud_foundry In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks. 0.9% —
CVE-2017-8041 MED 6.1 vmware single_sign-on_for_pivotal_cloud_foundry In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name. 0.9% —