58.650 CVE tracked
798 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2020-1960 | MED 4.7 | apache flink A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 to 1.6.4, 1.7.0 to 1.7.2, 1.8.0 to 1.8.3, 1.9.0 to 1.9.2, 1.10.0) where, when running a process with an enabled JMXReporter, with a port conf | 0.9% | — |
| CVE-2020-0789 | HIGH 7.1 | microsoft visual_studio_2019 A denial of service vulnerability exists when the Visual Studio Extension Installer Service improperly handles hard links, aka 'Visual Studio Extension Installer Service Denial of Service Vulnerability'. | 0.9% | — |
| CVE-2018-1360 | HIGH 8.1 | fortinet fortimanager A cleartext transmission of sensitive information vulnerability in Fortinet FortiManager 5.2.0 through 5.2.7, 5.4.0 and 5.4.1 may allow an unauthenticated attacker in a man in the middle position to retrieve the admin password via intercepting REST API JSON re | 0.9% | — |
| CVE-2018-0217 | MED 6.7 | cisco asr_5000_firmware A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected system. The vulnerability is due to insuffi | 0.9% | — |
| CVE-2017-0449 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged proc | 0.9% | — |
| CVE-2017-0447 | HIGH 7.0 | google android An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 0.9% | — |
| CVE-2017-0446 | HIGH 7.0 | google android An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process | 0.9% | — |
| CVE-2017-0442 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 0.9% | — |
| CVE-2017-0440 | HIGH 7.0 | google android An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. | 0.9% | — |
| CVE-2016-5235 | MED 6.1 | f5 websafe_alert_server A Cross Site Scripting (XSS) vulnerability in versions of F5 WebSafe Dashboard 3.9.x and earlier, aka F5 WebSafe Alert Server, allows an unauthenticated user to inject HTML via a crafted alert. | 0.9% | — |
| CVE-2026-69641 | CRIT 9.1 | microsoft exchange_server Missing authorization in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-66309 | CRIT 9.1 | microsoft azure_sql_database Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2026-24306 | CRIT 9.8 | microsoft azure_front_door Improper access control in Azure Front Door (AFD) allows an unauthorized attacker to elevate privileges over a network. | 0.9% | — |
| CVE-2025-27742 | MED 5.5 | microsoft windows_10_1507 Out-of-bounds read in Windows NTFS allows an unauthorized attacker to disclose information locally. | 0.9% | — |
| CVE-2024-30323 | HIGH 7.8 | foxit pdf_editor Foxit PDF Reader template Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in | 0.9% | — |
| CVE-2020-7860 | HIGH 7.8 | unegg_project unegg UnEGG v0.5 and eariler versions have a Integer overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by UnEGG. Attackers could exploit this and arbitrary code execution. This issue affects: Estsoft UnEGG 0.5 version | 0.9% | — |
| CVE-2018-15426 | MED 4.8 | cisco unity_connection A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is du | 0.9% | — |
| CVE-2018-0047 | HIGH 8.0 | juniper junos_space A persistent cross-site scripting vulnerability in the UI framework used by Junos Space Security Director may allow authenticated users to inject persistent and malicious scripts. This may allow stealing of information or performing actions as a different user | 0.9% | — |
| CVE-2017-15703 | MED 5.0 | apache nifi Any authenticated user (valid client certificate but without ACL permissions) could upload a template which contained malicious code and caused a denial of service via Java deserialization attack. The fix to properly handle Java deserialization was applied on | 0.9% | — |
| CVE-2017-0336 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user per | 0.9% | — |
| CVE-2017-0334 | MED 5.5 | linux linux_kernel An information disclosure vulnerability in the NVIDIA GPU driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as High because it could be used to access sensitive data without explicit user per | 0.9% | — |
| CVE-2026-65083 | CRIT 9.9 | nvidia openshell NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, infor | 0.9% | — |
| CVE-2026-43186 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: fix heap buffer overflow in __ioam6_fill_trace_data() On the receive path, __ioam6_fill_trace_data() uses trace->nodelen to decide how much data to write for each node. It trusts | 0.9% | — |
| CVE-2024-49032 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.9% | — |
| CVE-2024-38582 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix potential hang in nilfs_detach_log_writer() Syzbot has reported a potential hang in nilfs_detach_log_writer() called during nilfs2 unmount. Analysis revealed that this is becaus | 0.9% | — |