CVE Tracker
Track known exploited vulnerabilities, CISA KEV alerts, and linked threat intelligence.
1,542
Total CVEs
1,542
CISA KEV
1542
Critical & High
Mar 13, 2026
Last KEV Update
| CVE ID | Severity | Vendor | Description | Published | KEV |
|---|---|---|---|---|---|
| CVE-2020-0683 | High | MicrosoftWindows | Microsoft Windows Installer contains a privilege escalation vulnerability when MSI packages process symbolic links, which allows attackers to bypass access restrictions to add or remove files. | Nov 3, 2021 | KEV |
| CVE-2020-1350 | High | MicrosoftWindows | Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. | Nov 3, 2021 | KEV |
| CVE-2017-8759 | High | Microsoft.NET Framework | Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system. | Nov 3, 2021 | KEV |
| CVE-2019-4716 | High | IBMPlanning Analytics | IBM Planning Analytics is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. | Nov 3, 2021 | KEV |
| CVE-2016-3715 | High | ImageMagickImageMagick | ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading. | Nov 3, 2021 | KEV |
| CVE-2016-3718 | High | ImageMagickImageMagick | ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image. | Nov 3, 2021 | KEV |
| CVE-2021-30116 | High | KaseyaVirtual System/Server Administrator (VSA) | Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system. | Nov 3, 2021 | KEV |
| CVE-2020-7961 | High | LiferayLiferay Portal | Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services. | Nov 3, 2021 | KEV |
| CVE-2021-23874 | High | McAfeeMcAfee Total Protection (MTP) | McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense. | Nov 3, 2021 | KEV |
| CVE-2021-22506 | High | Micro FocusMicro Focus Access Manager | Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used. | Nov 3, 2021 | KEV |
| CVE-2021-22502 | High | Micro FocusOperation Bridge Reporter (OBR) | Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | KEV |
| CVE-2021-38647 | High | MicrosoftOpen Management Infrastructure (OMI) | Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution. | Nov 3, 2021 | KEV |
| CVE-2020-0878 | High | MicrosoftEdge and Internet Explorer | Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user. | Nov 3, 2021 | KEV |
| CVE-2020-17087 | High | MicrosoftWindows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | KEV |
| CVE-2021-33742 | High | MicrosoftWindows | Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for remote code execution. | Nov 3, 2021 | KEV |
| CVE-2021-31199 | High | MicrosoftEnhanced Cryptographic Provider | Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | KEV |
| CVE-2021-33771 | High | MicrosoftWindows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | KEV |
| CVE-2021-31956 | High | MicrosoftWindows | Microsoft Windows New Technology File System (NTFS) contains an unspecified vulnerability that allows attackers to escalate privileges via a specially crafted application. | Nov 3, 2021 | KEV |
| CVE-2021-31979 | High | MicrosoftWindows | Microsoft Windows kernel contains an unspecified vulnerability that allows for privilege escalation. | Nov 3, 2021 | KEV |
| CVE-2020-0938 | High | MicrosoftWindows | Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. | Nov 3, 2021 | KEV |