IT
58.646 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.646 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2017-10604 MED 5.3 juniper junos When the device is configured to perform account lockout with a defined period of time, any unauthenticated user attempting to log in as root with an incorrect password can trigger a lockout of the root account. When an SRX Series device is in cluster mode, an 0.9% —
CVE-2011-2822 HIGH 10.0 google chrome Google Chrome before 13.0.782.215 on Windows does not properly parse URLs located on the command line, which has unspecified impact and attack vectors. 0.9% —
CVE-2026-69304 MED 5.9 microsoft .net Improper handling of highly compressed data (data amplification) in ASP.NET Core allows an unauthorized attacker to deny service over a network. 0.9% —
CVE-2026-58523 MED 6.5 microsoft edge_chromium Improper access control in Microsoft Edge for Android allows an unauthorized attacker to bypass a security feature over a network. 0.9% —
CVE-2026-57993 HIGH 7.4 microsoft edge_chromium Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. 0.9% —
CVE-2026-45489 MED 6.5 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 0.9% —
CVE-2024-44985 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: prevent possible UAF in ip6_xmit() If skb_expand_head() returns NULL, skb has been freed and the associated dst/idev could also have been freed. We must use rcu_read_lock() to prevent 0.9% —
CVE-2023-24492 CRIT 9.6 citrix secure_access_client A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts. 0.9% —
CVE-2022-44730 MED 4.4 apache xml_graphics_batik Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL. 0.9% —
CVE-2022-38650 CRIT 10.0 vmware hyperic_server A remote unauthenticated insecure deserialization vulnerability exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to run arbitrary code or malware within Hyperic Server and the host operating system with the pr 0.9% —
CVE-2022-24550 HIGH 7.8 microsoft windows_10 Windows Telephony Server Elevation of Privilege Vulnerability 0.9% —
CVE-2022-20937 MED 5.3 cisco identity_services_engine A vulnerability in a feature that monitors RADIUS requests on Cisco Identity Services Engine (ISE) Software could allow an unauthenticated, remote attacker to negatively affect the performance of an affected device. This vulnerability is due to insufficient 0.9% —
CVE-2021-38637 MED 5.5 microsoft windows_10 Windows Storage Information Disclosure Vulnerability 0.9% —
CVE-2021-38636 MED 5.5 microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability 0.9% —
CVE-2021-38635 MED 5.5 microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability 0.9% —
CVE-2021-36972 MED 5.5 microsoft windows_10 Windows SMB Information Disclosure Vulnerability 0.9% —
CVE-2021-36969 MED 5.5 microsoft windows_10 Windows Redirected Drive Buffering SubSystem Driver Information Disclosure Vulnerability 0.9% —
CVE-2021-0226 HIGH 7.1 juniper junos_os_evolved On Juniper Networks Junos OS Evolved devices, receipt of a specific IPv6 packet may cause an established IPv6 BGP session to terminate, creating a Denial of Service (DoS) condition. Continued receipt and processing of this packet will create a sustained Denial 0.9% —
CVE-2020-1254 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Modules Installer Service improperly handles class object members.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows Modules Installer Service Elev 0.9% —
CVE-2020-1201 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way the Windows Now Playing Session Manager handles objects in memory, aka 'Windows Now Playing Session Manager Elevation of Privilege Vulnerability'. 0.9% —
CVE-2020-1199 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Feedback Hub improperly handles objects in memory, aka 'Windows Feedback Hub Elevation of Privilege Vulnerability'. 0.9% —
CVE-2020-1197 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Windows Error Reporting manager improperly handles a process crash, aka 'Windows Error Reporting Manager Elevation of Privilege Vulnerability'. 0.9% —
CVE-2020-0916 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0915. 0.9% —
CVE-2020-0915 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, aka 'Windows GDI Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0916. 0.9% —
CVE-2020-0898 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Graphics Component improperly handles objects in memory, aka 'Windows Graphics Component Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0791. 0.9% —