IT
58.450 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.450 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2024-38225 HIGH 8.8 microsoft dynamics_365_business_central Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability 1.4% —
CVE-2024-26189 HIGH 8.0 microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability 1.4% —
CVE-2023-28353 HIGH 8.8 faronics insight An issue was discovered in Faronics Insight 10.0.19045 on Windows. An unauthenticated attacker is able to upload any type of file to any location on the Teacher Console's computer, enabling a variety of different exploitation paths including code execution. It 1.4% —
CVE-2021-40461 HIGH 8.0 microsoft windows_10 Windows Hyper-V Remote Code Execution Vulnerability 1.4% —
CVE-2020-36565 MED 5.3 labstack echo Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read. 1.4% —
CVE-2015-0604 MED 5.0 cisco unified_ip_phones_9951_firmware The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424. 1.4% —
CVE-2014-3764 MED 4.3 paloaltonetworks pan-os Cross-site scripting (XSS) vulnerability in the web-based device management interface in Palo Alto Networks PAN-OS before 5.0.15, 5.1.x before 5.1.10, and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors 1.4% —
CVE-2022-24523 MED 4.3 microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability 1.4% —
CVE-2020-7849 HIGH 8.0 uprism curix A vulnerability of uPrism.io CURIX(Video conferecing solution) could allow an unauthenticated attacker to execute arbitrary code. This vulnerability is due to insufficient input(server domain) validation. An attacker could exploit this vulnerability through cr 1.4% —
CVE-2020-3399 HIGH 8.6 cisco ios_xe A vulnerability in the Control and Provisioning of Wireless Access Points (CAPWAP) protocol processing of Cisco IOS XE Software for Cisco Catalyst 9800 Series Wireless Controllers could allow an unauthenticated, remote attacker to cause a denial of service (Do 1.4% —
CVE-2019-6985 HIGH 8.8 foxitsoftware 3d An issue was discovered in Foxit 3D Plugin Beta before 9.4.0.16807 for Foxit Reader and PhantomPDF. The application could encounter an Out-of-Bounds Read in Indexing or a Heap Overflow and crash during handling of certain PDF files that embed specifically craf 1.4% —
CVE-2019-6647 MED 5.3 f5 big-ip_access_policy_manager On BIG-IP 14.1.0-14.1.0.5, 14.0.0-14.0.0.4, 13.0.0-13.1.2, 12.1.0-12.1.4.1, 11.5.2-11.6.4, when processing authentication attempts for control-plane users MCPD leaks a small amount of memory. Under rare conditions attackers with access to the management interf 1.4% —
CVE-2019-1905 MED 5.8 cisco email_security_appliance A vulnerability in the GZIP decompression engine of Cisco AsyncOS Software for Cisco Email Security Appliance (ESA) could allow an unauthenticated, remote attacker to bypass configured content filters on the device. The vulnerability is due to improper validat 1.4% —
CVE-2019-0066 HIGH 7.5 juniper junos An unexpected status return value weakness in the Next-Generation Multicast VPN (NG-mVPN) service of Juniper Networks Junos OS allows attacker to cause a Denial of Service (DoS) condition and core the routing protocol daemon (rpd) process when a specific malfo 1.4% —
CVE-2015-6350 MED 6.5 cisco prime_service_catalog SQL injection vulnerability in the web framework in Cisco Prime Service Catalog 11.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuw50843. 1.4% —
CVE-2015-6345 MED 6.5 cisco secure_access_control_server SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuw24700. 1.4% —
CVE-2013-1143 HIGH 7.1 cisco ios The RSVP protocol implementation in Cisco IOS 12.2 and 15.0 through 15.2 and IOS XE 3.1.xS through 3.4.xS before 3.4.5S and 3.5.xS through 3.7.xS before 3.7.2S, when MPLS-TE is enabled, allows remote attackers to cause a denial of service (incorrect memory acc 1.4% —
CVE-2025-29807 HIGH 8.7 microsoft dataverse Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network. 1.4% —
CVE-2018-15317 HIGH 7.5 f5 big-ip_access_policy_manager In BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, and 11.2.1-11.6.3.2, an attacker sending specially crafted SSL records to a SSL Virtual Server will cause corruption in the SSL data structures leading to intermittent decrypt BAD_RECORD_MAC errors. 1.4% —
CVE-2018-0827 MED 5.3 microsoft windows_10 Windows Scripting Host (WSH) in Windows 10 versions 1703 and 1709 and Windows Server, version 1709 allows a Device Guard security feature bypass vulnerability due to the way objects are handled in memory, aka "Windows Security Feature Bypass Vulnerability". 1.4% —
CVE-2017-7765 HIGH 7.5 mozilla firefox The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is 1.4% —
CVE-2016-6785 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ 1.4% —
CVE-2016-6782 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ 1.4% —
CVE-2016-6781 HIGH 7.0 linux linux_kernel An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Produ 1.4% —
CVE-2016-3346 HIGH 7.8 microsoft windows_10 Microsoft Windows 10 Gold, 1511, and 1607 does not properly enforce permissions, which allows local users to obtain Administrator access via a crafted DLL, aka "Windows Permissions Enforcement Elevation of Privilege Vulnerability." 1.4% —