58.568 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.568 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-48804 | MED 6.8 | microsoft windows_10_1507 Acceptance of extraneous untrusted data with trusted data in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack. | 0.6% | — |
| CVE-2025-21281 | HIGH 7.8 | microsoft windows_10_1507 Microsoft COM for Windows Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-33863 | CRIT 9.8 | linqi linqi An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file inclusion. | 0.6% | — |
| CVE-2024-26936 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate request buffer size in smb2_allocate_rsp_buf() The response buffer should be allocated in smb2_allocate_rsp_buf before validating request. But the fields in payload as well a | 0.6% | — |
| CVE-2024-26890 | HIGH 7.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btrtl: fix out of bounds memory access The problem is detected by KASAN. btrtl driver uses private hci data to store 'struct btrealtek_data'. If btrtl driver is used with btusb, t | 0.6% | — |
| CVE-2023-41267 | HIGH 7.8 | apache airflow_hdfs_provider In the Apache Airflow HDFS Provider, versions prior to 4.1.1, a documentation info pointed users to an install incorrect pip package. As this package name was unclaimed, in theory, an attacker could claim this package and provide code that would be executed wh | 0.6% | — |
| CVE-2023-23395 | LOW 3.1 | microsoft sharepoint_foundation Microsoft SharePoint Server Spoofing Vulnerability | 0.6% | — |
| CVE-2021-27072 | HIGH 7.0 | microsoft windows_10 Win32k Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2019-1846 | HIGH 7.4 | cisco ios_xr A vulnerability in the Multiprotocol Label Switching (MPLS) Operations, Administration, and Maintenance (OAM) implementation of Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an unauthenticated, adjacent attacker to tr | 0.6% | — |
| CVE-2019-1749 | HIGH 7.4 | cisco ios_xe A vulnerability in the ingress traffic validation of Cisco IOS XE Software for Cisco Aggregation Services Router (ASR) 900 Route Switch Processor 3 (RSP3) could allow an unauthenticated, adjacent attacker to trigger a reload of an affected device, resulting in | 0.6% | — |
| CVE-2018-11760 | MED 5.5 | apache spark When using PySpark , it's possible for a different local user to connect to the Spark application and impersonate the user running the Spark application. This affects versions 1.x, 2.0.x, 2.1.x, 2.2.0 to 2.2.2, and 2.3.0 to 2.3.1. | 0.6% | — |
| CVE-2017-2583 | HIGH 8.4 | linux linux_kernel The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulates a "MOV SS, NULL selector" instruction, which allows guest OS users to cause a denial of service (guest OS crash) or gain guest OS privileg | 0.6% | — |
| CVE-2026-62873 | CRIT 9.8 | microsoft windows_admin_center Improper verification of cryptographic signature in Microsoft 365 Admin Center allows an unauthorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-43466 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix DMA FIFO desync on error CQE SQ recovery In case of a TX error CQE, a recovery flow is triggered, mlx5e_reset_txqsq_cc_pc() resets dma_fifo_cc to 0 but not dma_fifo_pc, desync | 0.6% | — |
| CVE-2026-20955 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2026-20948 | HIGH 7.8 | microsoft 365_apps Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2025-21748 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix integer overflows on 32 bit systems On 32bit systems the addition operations in ipc_msg_alloc() can potentially overflow leading to memory corruption. Add bounds checking using KS | 0.6% | — |
| CVE-2024-57802 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netrom: check buffer length before accessing it Syzkaller reports an uninit value read from ax25cmp when sending raw message through ieee802154 implementation. ============================= | 0.6% | — |
| CVE-2024-50076 | MED 6.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: vt: prevent kernel-infoleak in con_font_get() font.data may not initialize all memory spaces depending on the implementation of vc->vc_sw->con_font_get. This may cause info-leak, so to preve | 0.6% | — |
| CVE-2024-46736 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double put of @cfile in smb2_rename_path() If smb2_set_path_attr() is called with a valid @cfile and returned -EINVAL, we need to call cifs_get_writable_path() again as the | 0.6% | — |
| CVE-2024-40992 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix responder length checking for UD request packets According to the IBA specification: If a UD request packet is detected with an invalid length, the request shall be an invalid | 0.6% | — |
| CVE-2024-38142 | HIGH 7.8 | microsoft windows_10_1507 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-35888 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: erspan: make sure erspan_base_hdr is present in skb->head syzbot reported a problem in ip6erspan_rcv() [1] Issue is that ip6erspan_rcv() (and erspan_rcv()) no longer make sure erspan_base_h | 0.6% | — |
| CVE-2024-32118 | MED 6.7 | fortinet fortianalyzer Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7. | 0.6% | — |
| CVE-2024-26857 | HIGH 7.3 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: geneve: make sure to pull inner header in geneve_rx() syzbot triggered a bug in geneve_rx() [1] Issue is similar to the one I fixed in commit 8d975c15c0cd ("ip6_tunnel: make sure to pull in | 0.6% | — |