58.306 CVE tracked
790 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.306 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sorted descending | Product and flaw | EPSS, sort descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-43242 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.2% | — |
| CVE-2021-41372 | HIGH 7.6 | microsoft power_bi_report_server A Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) vulnerability exists when Power BI Report Server Template file (pbix) containing HTML files is uploaded to the server and HTML files are accessed directly by the victim. Combining these 2 vulne | 0.7% | — |
| CVE-2021-40484 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2021-40483 | HIGH 7.6 | microsoft sharepoint_server Microsoft SharePoint Server Spoofing Vulnerability | 1.4% | — |
| CVE-2021-38652 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2021-38651 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2021-38650 | HIGH 7.6 | microsoft 365_apps Microsoft Office Spoofing Vulnerability | 1.6% | — |
| CVE-2021-36940 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 4.0% | — |
| CVE-2021-31984 | HIGH 7.6 | microsoft power_bi_report_server Power BI Remote Code Execution Vulnerability | 1.9% | — |
| CVE-2021-31964 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.5% | — |
| CVE-2021-31950 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 4.6% | — |
| CVE-2021-31948 | HIGH 7.6 | microsoft sharepoint_enterprise_server Microsoft SharePoint Server Spoofing Vulnerability | 1.3% | — |
| CVE-2021-31206 | HIGH 7.6 | microsoft exchange_server Microsoft Exchange Server Remote Code Execution Vulnerability | 13.0% | — |
| CVE-2021-28478 | HIGH 7.6 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 1.6% | — |
| CVE-2021-27059 | HIGH 7.6 | microsoft office Microsoft Office Remote Code Execution Vulnerability | 6.1% | |
| CVE-2021-22123 | HIGH 7.6 | fortinet fortiweb An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated attacker to execute arbitrary commands on the system via the SAML server configuration page. | 77.3% | — |
| CVE-2020-4509 | HIGH 7.6 | ibm qradar_security_information_and_event_manager IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 182364. | 1.5% | — |
| CVE-2020-16872 | HIGH 7.6 | microsoft dynamics_365 <p>A cross site scripting vulnerability exists when Microsoft Dynamics 365 (on-premises) does not properly sanitize a specially crafted web request to an affected Dynamics server. An authenticated attacker could exploit the vulnerability by sending a specially | 1.8% | — |
| CVE-2020-1593 | HIGH 7.6 | microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.</p> <p>There are multiple ways an attacker could exp | 2.8% | — |
| CVE-2020-1508 | HIGH 7.6 | microsoft windows_10 <p>A remote code execution vulnerability exists when Windows Media Audio Decoder improperly handles objects. An attacker who successfully exploited the vulnerability could take control of an affected system.</p> <p>There are multiple ways an attacker could exp | 3.3% | — |
| CVE-2019-1807 | HIGH 7.6 | cisco umbrella A vulnerability in the session management functionality of the web UI for the Cisco Umbrella Dashboard could allow an authenticated, remote attacker to access the Dashboard via an active, user session. The vulnerability exists due to the affected application n | 1.5% | — |
| CVE-2019-0965 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 1.3% | — |
| CVE-2019-0709 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 4.0% | — |
| CVE-2019-0620 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a | 1.4% | — |
| CVE-2018-0961 | HIGH 7.6 | microsoft windows_10 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate vSMB packet data, aka "Hyper-V vSMB Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | 3.2% | — |