58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-41293 | CRIT 9.8 | apache tomcat Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also | 1.7% | — |
| CVE-2023-33136 | HIGH 8.8 | microsoft azure_devops_server Azure DevOps Server Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2021-39053 | HIGH 7.5 | ibm spectrum_copy_data_management IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to obtain sensitive information, caused by the improper handling of requests for Spectrum Copy Data Management Admin Console. By sending a specially-crafted request, a remote at | 1.7% | — |
| CVE-2020-0615 | MED 5.5 | microsoft windows_10 An information disclosure vulnerability exists in the Windows Common Log File System (CLFS) driver when it fails to properly handle objects in memory, aka 'Windows Common Log File System Driver Information Disclosure Vulnerability'. This CVE ID is unique from | 1.7% | — |
| CVE-2015-0573 | CRIT 9.8 | linux linux_kernel drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (invalid pointer derefer | 1.7% | — |
| CVE-2015-0078 | HIGH 7.2 | microsoft windows_8 win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly validate the token of a calling thread, which allows local users to gain privileges via a crafted applicat | 1.7% | — |
| CVE-2010-0237 | MED 6.9 | microsoft windows_2000 The kernel in Microsoft Windows 2000 SP4 and XP SP2 and SP3 allows local users to gain privileges by creating a symbolic link from an untrusted registry hive to a trusted registry hive, aka "Windows Kernel Symbolic Link Creation Vulnerability." | 1.7% | — |
| CVE-2008-5044 | MED 4.0 | microsoft windows_server_2003 Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang) via a multi-threaded application that makes many calls to UnhookWindowsHookEx while certain other desktop activity is occurring. | 1.7% | — |
| CVE-2020-1191 | HIGH 7.8 | microsoft windows_10 An elevation of privilege vulnerability exists when the Windows State Repository Service improperly handles objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in an elevated context. An attacker could exploit | 1.7% | — |
| CVE-2019-17440 | CRIT 10.0 | paloaltonetworks pan-os Improper restriction of communications to Log Forwarding Card (LFC) on PA-7000 Series devices with second-generation Switch Management Card (SMC) may allow an attacker with network access to the LFC to gain root access to PAN-OS. This issue affects PAN-OS 9.0 | 1.7% | — |
| CVE-2004-1461 | HIGH 7.5 | cisco secure_access_control_server Cisco Secure Access Control Server (ACS) 3.2(3) and earlier spawns a separate unauthenticated TCP connection on a random port when a user authenticates to the ACS GUI, which allows remote attackers to bypass authentication by connecting to that port from the s | 1.7% | — |
| CVE-2025-33072 | HIGH 8.1 | microsoft msagsfeedback.azurewebsites.net Improper access control in Azure allows an unauthorized attacker to disclose information over a network. | 1.7% | — |
| CVE-2024-38202 | HIGH 7.3 | microsoft windows_10_1607 Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization | 1.7% | — |
| CVE-2024-38088 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2024-38087 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2022-41722 | HIGH 7.5 | golang go A path traversal vulnerability exists in filepath.Clean on Windows. On Windows, the filepath.Clean function could transform an invalid path such as "a/../c:/b" into the valid path "c:\b". This transformation of a relative (if invalid) path into an absolute pat | 1.7% | — |
| CVE-1999-1175 | HIGH 7.5 | cisco ios Web Cache Control Protocol (WCCP) in Cisco Cache Engine for Cisco IOS 11.2 and earlier does not use authentication, which allows remote attackers to redirect HTTP traffic to arbitrary hosts via WCCP packets to UDP port 2048. | 1.7% | — |
| CVE-2026-65788 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally. | 1.7% | — |
| CVE-2026-61929 | HIGH 7.0 | microsoft windows_11_23h2 Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally. | 1.7% | — |
| CVE-2021-46463 | CRIT 9.8 | f5 njs njs through 0.7.1, used in NGINX, was discovered to contain a control flow hijack caused by a Type Confusion vulnerability in njs_promise_perform_then(). | 1.7% | — |
| CVE-2011-0089 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri | 1.7% | — |
| CVE-2011-0086 | HIGH 7.2 | microsoft windows_2003_server win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly validate user-mode input, which allows local users to gain pri | 1.7% | — |
| CVE-2024-37336 | HIGH 8.8 | microsoft sql_server_2016 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | 1.7% | — |
| CVE-2019-17561 | HIGH 7.5 | apache netbeans The "Apache NetBeans" autoupdate system does not fully validate code signatures. An attacker could modify the downloaded nbm and include additional code. "Apache NetBeans" versions up to and including 11.2 are affected by this vulnerability. | 1.7% | — |
| CVE-2019-1203 | MED 5.4 | microsoft sharepoint_enterprise_server A cross-site-scripting (XSS) vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server. An authenticated attacker could exploit the vulnerability by sending a specially cra | 1.7% | — |