IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2025-29832 MED 6.5 microsoft windows_10_1507 Out-of-bounds read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2025-29830 MED 6.5 microsoft windows_10_1507 Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. 1.3% —
CVE-2025-27471 MED 5.9 microsoft windows_10_1507 Sensitive data storage in improperly locked memory in Microsoft Streaming Service allows an unauthorized attacker to deny service over a network. 1.3% —
CVE-2025-21286 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3% —
CVE-2025-21282 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3% —
CVE-2025-21273 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3% —
CVE-2025-21266 HIGH 8.8 microsoft windows_10_1507 Windows Telephony Service Remote Code Execution Vulnerability 1.3% —
CVE-2020-3537 MED 5.7 cisco jabber A vulnerability in Cisco Jabber for Windows software could allow an authenticated, remote attacker to gain access to sensitive information. The vulnerability is due to improper validation of message contents. An attacker could exploit this vulnerability by sen 1.3% —
CVE-2020-16961 HIGH 7.8 microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability 1.3% —
CVE-2020-16960 HIGH 7.8 microsoft windows_10 Windows Backup Engine Elevation of Privilege Vulnerability 1.3% —
CVE-2016-9217 HIGH 8.8 cisco intercloud_fabric A vulnerability in Cisco Intercloud Fabric for Business and Cisco Intercloud Fabric for Providers could allow an unauthenticated, remote attacker to connect to the database used by these products. More Information: CSCus99394. Known Affected Releases: 7.3(0)ZN 1.3% —
CVE-2015-0588 MED 6.8 cisco unified_communications_domain_manager Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo77055. 1.3% —
CVE-2014-3305 MED 6.8 cisco webex_meetings_server Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco WebEx Meetings Server 1.5(.1.131) and earlier allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCuj81735. 1.3% —
CVE-2003-1305 MED 5.0 Microsoft Internet Explorer allows remote attackers to cause a denial of service (resource consumption) via a Javascript src attribute that recursively loads the current web page. 1.3% —
CVE-2026-76433 MED 5.3 cisco identity_services_engine A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory tra 1.3% —
CVE-2024-21390 HIGH 7.1 microsoft authenticator Microsoft Authenticator Elevation of Privilege Vulnerability 1.3% —
CVE-2023-33144 MED 6.6 microsoft visual_studio_code Visual Studio Code Spoofing Vulnerability 1.3% —
CVE-2017-3887 MED 5.9 cisco secure_firewall_threat_defense A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco Firepower System Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition because the Snort process unexpectedly rest 1.3% —
CVE-2024-38129 HIGH 7.5 microsoft windows_server_2022_23h2 Windows Kerberos Elevation of Privilege Vulnerability 1.3% —
CVE-2024-25693 CRIT 9.9 esri portal_for_arcgis There is a path traversal in Esri Portal for ArcGIS versions <= 11.2. Successful exploitation may allow a remote, authenticated attacker to traverse the file system to access files or execute code outside of the intended directory.  1.3% —
CVE-2023-48791 HIGH 8.8 fortinet fortiportal An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized c 1.3% —
CVE-2023-20855 HIGH 8.8 vmware vrealize_automation VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orchestrator, may be able to use specially crafted input to bypass XML parsing restrictions leading to access to sen 1.3% —
CVE-2019-1053 MED 6.3 microsoft windows_10 An elevation of privilege vulnerability exists when the Windows Shell fails to validate folder shortcuts. An attacker who successfully exploited the vulnerability could elevate privileges by escaping a sandbox. To exploit this vulnerability, an attacker would 1.3% —
CVE-2018-0269 MED 4.3 cisco digital_network_architecture_center A vulnerability in the web framework of the Cisco Digital Network Architecture Center (DNA Center) could allow an unauthenticated, remote attacker to communicate with the Kong API server without restriction. The vulnerability is due to an overly permissive Cro 1.3% —
CVE-2016-1324 MED 5.3 cisco spark The REST interface in Cisco Spark 2015-06 allows remote attackers to cause a denial of service (resource outage) by accessing an administrative page, aka Bug ID CSCuv84125. 1.3% —