58.575 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.575 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-36569 | HIGH 8.4 | microsoft 365_apps Microsoft Office Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-37979 | HIGH 7.8 | microsoft windows_10 Windows Hyper-V Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-41020 | HIGH 8.8 | fortinet fortiisolator An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL. | 0.6% | — |
| CVE-2021-24092 | HIGH 7.8 | microsoft endpoint_protection Microsoft Defender Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2014-4700 | MED 4.9 | citrix xendesktop Citrix XenDesktop 7.x, 5.x, and 4.x, when pooled random desktop groups is enabled and ShutdownDesktopsAfterUse is disabled, allows local guest users to gain access to another user's desktop via unspecified vectors. | 0.6% | — |
| CVE-2012-5459 | HIGH 7.9 | vmware player Untrusted search path vulnerability in VMware Workstation 8.x before 8.0.5 and VMware Player 4.x before 4.0.5 on Windows allows host OS users to gain host OS privileges via a Trojan horse DLL in a "system folder." | 0.6% | — |
| CVE-2026-56188 | CRIT 9.8 | microsoft windows_10_1607 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Network driver allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-45497 | HIGH 7.7 | microsoft copilot Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-22068 | HIGH 8.2 | apache traffic_server Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue. | 0.6% | — |
| CVE-2026-19297 | CRIT 9.1 | langflow langflow IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | 0.6% | — |
| CVE-2025-21844 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: Add check for next_buffer in receive_encrypted_standard() Add check for the return value of cifs_buf_get() and cifs_small_buf_get() in receive_encrypted_standard() to prevent nu | 0.6% | — |
| CVE-2025-10226 | CRIT 9.8 | axxonsoft axxon_one Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0.8 and earlier on Windows and Linux allows a remote attacker to escalate privileges, execute arbitrary code, or cause denial-of-service via e | 0.6% | — |
| CVE-2024-53058 | CRIT 9.4 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: stmmac: TSO: Fix unbalanced DMA map/unmap for non-paged SKB data In case the non-paged data of a SKB carries protocol header and protocol payload to be transmitted on a certain platform | 0.6% | — |
| CVE-2024-38218 | HIGH 8.4 | microsoft edge_chromium Microsoft Edge (HTML-based) Memory Corruption Vulnerability | 0.6% | — |
| CVE-2023-21531 | HIGH 7.0 | microsoft azure_service_fabric Azure Service Fabric Container Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-34690 | HIGH 7.1 | microsoft windows_10 Windows Fax Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-22215 | MED 6.5 | juniper junos A Missing Release of File Descriptor or Handle after Effective Lifetime vulnerability in plugable authentication module (PAM) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated attacker with low privileges to cause a Denial of Ser | 0.6% | — |
| CVE-2022-20965 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to take privileges actions within the web-based management interface. This vulnerability is due to improper access control | 0.6% | — |
| CVE-2021-22033 | LOW 2.7 | vmware cloud_foundation Releases prior to VMware vRealize Operations 8.6 contain a Server Side Request Forgery (SSRF) vulnerability. | 0.6% | — |
| CVE-2017-9489 | HIGH 8.8 | cisco dpc3939b_firmware The Comcast firmware on Cisco DPC3939B (firmware version dpc3939b-v303r204217-150321a-CMCST) devices allows configuration changes via CSRF. | 0.6% | — |
| CVE-2026-77898 | HIGH 7.5 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69607 | HIGH 7.5 | microsoft windows_10_1607 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-69397 | HIGH 7.5 | microsoft windows_10_1809 Use after free in OpenSSH for Windows allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-66315 | HIGH 7.5 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.6% | — |
| CVE-2026-59117 | HIGH 7.5 | microsoft terminal Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network. | 0.6% | — |