58.586 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.586 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21364 | CRIT 9.3 | microsoft azure_site_recovery Microsoft Azure Site Recovery Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2023-28291 | HIGH 8.4 | microsoft raw_image_extension Raw Image Extension Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-23398 | HIGH 7.1 | microsoft 365_apps Microsoft Excel Spoofing Vulnerability | 0.6% | — |
| CVE-2022-38170 | MED 4.7 | apache airflow In Apache Airflow prior to 2.3.4, an insecure umask was configured for numerous Airflow components when running with the `--daemon` flag which could result in a race condition giving world-writable files in the Airflow home directory and allowing local users t | 0.6% | — |
| CVE-2021-42300 | MED 6.0 | microsoft azure_sphere Azure Sphere Tampering Vulnerability | 0.6% | — |
| CVE-2021-25252 | MED 5.5 | trendmicro apex_central Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | 0.6% | — |
| CVE-2020-7053 | HIGH 7.8 | linux linux_kernel In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c. This is related to i915_ | 0.6% | — |
| CVE-2020-3589 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) Software could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. | 0.6% | — |
| CVE-2020-3491 | MED 5.5 | cisco vision_dynamic_signage_director A vulnerability in the web-based management interface of Cisco Vision Dynamic Signage Director could allow an authenticated, remote attacker with administrative privileges to conduct a cross-site scripting (XSS) attack against a user of the interface on an aff | 0.6% | — |
| CVE-2020-3464 | MED 4.8 | cisco ucs_director A vulnerability in the web-based management interface of Cisco UCS Director could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists b | 0.6% | — |
| CVE-2020-26083 | MED 4.8 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative credentials to conduct a cross-site scripting (XSS) attack against a user of the interface. The vuln | 0.6% | — |
| CVE-2020-10732 | LOW 3.3 | canonical ubuntu_linux A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. | 0.6% | — |
| CVE-2016-6375 | MED 5.3 | cisco wireless_lan_controller_software Cisco Wireless LAN Controller (WLC) devices before 8.0.140.0, 8.1.x and 8.2.x before 8.2.121.0, and 8.3.x before 8.3.102.0 allow remote attackers to cause a denial of service (device reload) by sending crafted Inter-Access Point Protocol (IAPP) packets and the | 0.6% | — |
| CVE-2004-2013 | HIGH 7.8 | linux linux_kernel Integer overflow in the SCTP_SOCKOPT_DEBUG_NAME SCTP socket option in socket.c in the Linux kernel 2.4.25 and earlier allows local users to execute arbitrary code via an optlen value of -1, which causes kmalloc to allocate 0 bytes of memory. | 0.6% | — |
| CVE-2026-65948 | HIGH 7.3 | apache ranger UnixAuth lacks brute-force protection in Apache Ranger versions <= 2.8.0. Note: UnixAuth is NOT a recommended option for production deployments. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 0.6% | — |
| CVE-2026-52986 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: don't use simple_strtoul Replace unsafe port parsing in epaddr_len(), ct_sip_parse_header_uri(), and ct_sip_parse_request() with a new sip_parse_port() helper th | 0.6% | — |
| CVE-2025-55244 | CRIT 9.0 | microsoft azure_ai_bot_service Azure Bot Service Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2025-21275 | HIGH 7.8 | microsoft windows_10_21h2 Windows App Package Installer Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-56640 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net/smc: fix LGR and link use-after-free issue We encountered a LGR/link use-after-free issue, which manifested as the LGR/link refcnt reaching 0 early and entering the clear process, making | 0.6% | — |
| CVE-2024-43571 | MED 5.6 | microsoft windows_11_24h2 Sudo for Windows Spoofing Vulnerability | 0.6% | — |
| CVE-2024-35870 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix UAF in smb2_reconnect_server() The UAF bug is due to smb2_reconnect_server() accessing a session that is already being teared down by another thread that is executing __cifs | 0.6% | — |
| CVE-2022-49003 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: nvme: fix SRCU protection of nvme_ns_head list Walking the nvme_ns_head siblings list is protected by the head's srcu in nvme_ns_head_submit_bio() but not nvme_mpath_revalidate_paths(). Remo | 0.6% | — |
| CVE-2022-37997 | HIGH 7.8 | microsoft windows_10 Windows Graphics Component Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2026-9182 | CRIT 9.8 | esri arcgis_server Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endpoint. Successful exploitation could allow arbitrary file upload, potentially allowing fo | 0.6% | — |
| CVE-2026-81380 | MED 5.3 | microsoft visual_studio_code Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network. | 0.6% | — |