IT
58.127 CVE tracked
788 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.127 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2014-5711 MED 5.4 microsoft microsoft_tech_companion The Microsoft Tech Companion (aka com.technet) application 1.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. 2.7%
CVE-2023-38185 HIGH 8.8 microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability 2.7%
CVE-2021-27047 HIGH 7.8 microsoft high_efficiency_video_coding HEVC Video Extensions Remote Code Execution Vulnerability 2.7%
CVE-2020-16934 HIGH 7.0 microsoft 365_apps <p>An elevation of privilege vulnerability exists in the way that Microsoft Office Click-to-Run (C2R) AppVLP handles certain files. An attacker who successfully exploited the vulnerability could elevate privileges.</p> <p>To exploit this vulnerability, an atta 2.7%
CVE-2020-1582 HIGH 7.8 microsoft 365_apps A remote code execution vulnerability exists in Microsoft Access software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the 2.7%
CVE-2020-1534 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Backup Service improperly handles file operations. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafte 2.7%
CVE-2020-1531 HIGH 7.8 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Accounts Control improperly handles memory. To exploit this vulnerability, an attacker would first have to gain execution on the victim system. An attacker could then run a specially crafted appli 2.7%
CVE-2020-1478 HIGH 7.8 microsoft windows_10 A memory corruption vulnerability exists when Windows Media Foundation improperly handles objects in memory. An attacker who successfully exploited the vulnerability could install programs; view, change, or delete data; or create new accounts with full user ri 2.7%
CVE-2008-2739 HIGH 7.8 cisco ios The SERVICE.DNS signature engine in the Intrusion Prevention System (IPS) in Cisco IOS 12.3 and 12.4 allows remote attackers to cause a denial of service (device crash or hang) via network traffic that triggers unspecified IPS signatures, a different vulnerabi 2.7%
CVE-2020-9616 MED 5.5 adobe premiere_pro Adobe Premiere Pro versions 14.1 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. 2.7%
CVE-2020-17115 HIGH 8.0 microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability 2.7%
CVE-2020-1345 HIGH 7.4 microsoft sharepoint_enterprise_server <p>A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially 2.7%
CVE-2023-29332 HIGH 7.5 microsoft azure_kubernetes_service Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability 2.7%
CVE-2020-1952 CRIT 9.8 apache iotdb An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely. 2.7%
CVE-2011-0154 MED 5.1 apple itunes WebKit, as used in Apple iTunes before 10.2 on Windows and Apple iOS, does not properly implement the .sort function for JavaScript arrays, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and a 2.7%
CVE-2025-59194 HIGH 7.0 microsoft windows_11_22h2 Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally. 2.7%
CVE-2023-23382 MED 6.5 microsoft azure_machine_learning Azure Machine Learning Compute Instance Information Disclosure Vulnerability 2.7%
CVE-2022-30189 MED 6.5 microsoft windows_10 Windows Autopilot Device Management and Enrollment Client Spoofing Vulnerability 2.7%
CVE-2020-24415 HIGH 7.8 adobe illustrator Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability require 2.7%
CVE-2015-8022 HIGH 7.5 f5 big-ip_access_policy_manager The Configuration utility in F5 BIG-IP LTM, Analytics, APM, ASM, GTM, and Link Controller 11.x before 11.2.1 HF16, 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, an 2.7%
CVE-2018-8254 MED 5.4 microsoft project_server An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.7%
CVE-2018-8252 MED 5.4 microsoft sharepoint_foundation An elevation of privilege vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka "Microsoft SharePoint Elevation of Privilege Vulnerability." This affects Microsoft 2.7%
CVE-2018-4201 HIGH 8.8 apple icloud An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affec 2.7%
CVE-2018-20243 HIGH 7.5 apache fineract The implementation of POST with the username and password in the URL parameters exposed the credentials. More infomration is available in fineract jira issues 726 and 629. 2.7%
CVE-2020-9482 MED 6.5 apache nifi_registry If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user clicks Log Out, NiFi Registry invalidates the authentication token on the client side but not on the server side. This permits the user's client-side token to be use 2.7%