IT
58.507 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.507 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2018-1261 MED 4.7 vmware spring_integration_zip Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So wh 1.2% —
CVE-2017-2290 HIGH 8.8 puppet mcollective-puppet-agent On Windows installations of the mcollective-puppet-agent plugin, version 1.12.0, a non-administrator user can create an executable that will be executed with administrator privileges on the next "mco puppet" run. Puppet Enterprise users are not affected. This 1.2% —
CVE-2026-42780 MED 4.9 f5 big-ip_ssl_orchestrator A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high privilege to overwrite, delete or corrupt arbitrary local files.  Note: Software versions which have reached End of Technical Support (EoTS) a 1.2% —
CVE-2025-27017 MED 6.5 apache nifi Apache NiFi 1.13.0 through 2.2.0 includes the username and password used to authenticate with MongoDB in the NiFi provenance events that MongoDB components generate during processing. An authorized user with read access to the provenance events of those proces 1.2% —
CVE-2023-36796 HIGH 7.8 microsoft .net Visual Studio Remote Code Execution Vulnerability 1.2% —
CVE-2023-36794 HIGH 7.8 microsoft .net Visual Studio Remote Code Execution Vulnerability 1.2% —
CVE-2023-36793 HIGH 7.8 microsoft .net Visual Studio Remote Code Execution Vulnerability 1.2% —
CVE-2023-36792 HIGH 7.8 microsoft .net Visual Studio Remote Code Execution Vulnerability 1.2% —
CVE-2022-22375 HIGH 7.2 ibm security_verify_privilege_on-premises IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681. 1.2% —
CVE-2021-40774 MED 5.5 adobe prelude Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of 1.2% —
CVE-2021-40773 MED 5.5 adobe prelude Adobe Prelude version 10.1 (and earlier) is affected by a null pointer dereference vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of 1.2% —
CVE-2021-31978 MED 5.5 microsoft malware_protection_engine Microsoft Defender Denial of Service Vulnerability 1.2% —
CVE-2020-2022 HIGH 7.5 paloaltonetworks pan-os An information exposure vulnerability exists in Palo Alto Networks Panorama software that discloses the token for the Panorama web interface administrator's session to a managed device when the Panorama administrator performs a context switch into that device. 1.2% —
CVE-2020-1420 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Error Reporting improperly handles file operations.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Error Reporting Information Disclosu 1.2% —
CVE-2020-1358 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Resource Policy component improperly handles memory.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Resource Policy Information Dis 1.2% —
CVE-2026-40858 HIGH 8.8 apache camel The camel-infinispan component's ProtoStream-based remote aggregation repository deserializes data read from a remote Infinispan cache using java.io.ObjectInputStream without applying any ObjectInputFilter. An attacker who can write to the Infinispan cache use 1.2% —
CVE-2023-34367 MED 6.5 microsoft windows_7 Windows 7 is vulnerable to a full blind TCP/IP hijacking attack. The vulnerability exists in Windows 7 (any Windows until Windows 8) and in any implementation of TCP/IP, which is vulnerable to the Idle scan attack (including many IoT devices). NOTE: The vendor 1.2% —
CVE-2020-1426 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1389, CVE-2020-1419. 1.2% —
CVE-2020-1391 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows Agent Activation Runtime (AarSvc) fails to properly handle objects in memory, aka 'Windows Agent Activation Runtime Information Disclosure Vulnerability'. 1.2% —
CVE-2020-1389 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel fails to properly initialize a memory address, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1367, CVE-2020-1419, CVE-2020-1426. 1.2% —
CVE-2020-1386 MED 5.5 microsoft windows_10 An information vulnerability exists when Windows Connected User Experiences and Telemetry Service improperly discloses file information, aka 'Connected User Experiences and Telemetry Service Information Disclosure Vulnerability'. 1.2% —
CVE-2020-1367 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-1389, CVE-2020-1419, CVE-2020-1426. 1.2% —
CVE-2020-1330 MED 5.5 microsoft windows_10 An information disclosure vulnerability exists when Windows Mobile Device Management (MDM) Diagnostics improperly handles junctions, aka 'Windows Mobile Device Management Diagnostics Information Disclosure Vulnerability'. 1.2% —
CVE-2012-1868 MED 6.9 microsoft windows_xp Race condition in the thread-creation implementation in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP3 allows local users to gain privileges via a crafted application, aka "Win32k.sys Race Condition Vulnerability." 1.2% —
CVE-2012-1867 HIGH 8.4 microsoft windows_2003_server Integer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted T 1.2% —