IT
58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-30474 MED 5.0 apache commons_vfs Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Commons VFS. The FtpFileObject class can throw an exception when a file is not found, revealing the original URI in its message, which may include a password. The fix is to mas 0.9% —
CVE-2024-42285 CRIT 9.8 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/iwcm: Fix a use-after-free related to destroying CM IDs iw_conn_req_handler() associates a new struct rdma_id_private (conn_id) with an existing struct iw_cm_id (cm_id) as follows: 0.9% —
CVE-2024-26216 HIGH 7.3 microsoft windows_server_2008 Windows File Server Resource Management Service Elevation of Privilege Vulnerability 0.9% —
CVE-2021-38634 HIGH 7.1 microsoft windows_10 Microsoft Windows Update Client Elevation of Privilege Vulnerability 0.9% —
CVE-2020-1088 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files. The vulnerability could allow elevation of privilege if an attacker can successfully exploit it. An attacker who successfully exploited the vul 0.9% —
CVE-2019-1948 MED 5.9 cisco webex_meetings A vulnerability in Cisco Webex Meetings Mobile (iOS) could allow an unauthenticated, remote attacker to gain unauthorized read access to sensitive data by using an invalid Secure Sockets Layer (SSL) certificate. The vulnerability is due to insufficient SSL cer 0.9% —
CVE-2018-13366 MED 5.3 fortinet fortios An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol. 0.9% —
CVE-2017-12273 MED 6.5 cisco aironet_1562_firmware A vulnerability in 802.11 association request frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthenticated, Layer 2 radio frequency (RF) adjacent attacker to cause the Access Point (AP) to reload, resulting in 0.9% —
CVE-2017-0438 HIGH 7.0 google android An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. 0.9% —
CVE-2017-0437 HIGH 7.0 google android An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. 0.9% —
CVE-2017-0436 HIGH 7.0 google android An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. 0.9% —
CVE-2017-0434 HIGH 7.0 google android An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the touchscreen chipset. This issue is rated as High because it first requires compromising a 0.9% —
CVE-2026-20824 MED 5.5 microsoft windows_10_1607 Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally. 0.9% —
CVE-2025-47955 HIGH 7.8 microsoft windows_10_1507 Improper privilege management in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. 0.9% —
CVE-2025-20354 CRIT 9.8 cisco unified_contact_center_express A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability 0.9% —
CVE-2024-50083 HIGH 7.5 linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: tcp: fix mptcp DSS corruption due to large pmtu xmit Syzkaller was able to trigger a DSS corruption: TCP: request_sock_subflow_v4: Possible SYN flooding on port [::]:20002. Sending cookie 0.9% —
CVE-2024-28897 MED 6.8 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 0.9% —
CVE-2024-24275 CRIT 9.6 teamwire teamwire Cross Site Scripting vulnerability in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the global search function. 0.9% —
CVE-2021-31356 HIGH 7.8 juniper junos_os_evolved A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the curre 0.9% —
CVE-2020-3154 MED 4.9 cisco cloud_web_security A vulnerability in the web UI of Cisco Cloud Web Security (CWS) could allow an authenticated, remote attacker to execute arbitrary SQL queries. The vulnerability exists because the web-based management interface improperly validates SQL values. An authenticate 0.9% —
CVE-2020-0644 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when Microsoft Windows implements predictable memory section names, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0635. 0.9% —
CVE-2019-19489 MED 5.5 smplayer smplayer SMPlayer 19.5.0 has a buffer overflow via a long .m3u file. 0.9% —
CVE-2019-1701 MED 4.8 cisco adaptive_security_appliance_software Multiple vulnerabilities in the WebVPN service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of 0.9% —
CVE-2019-14814 HIGH 7.8 canonical ubuntu_linux There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. 0.9% —
CVE-2017-5657 HIGH 8.0 apache archiva Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva services 0.9% —