58.614 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.614 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-42108 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: rswitch: Avoid use-after-free in rswitch_poll() The use-after-free is actually in rswitch_tx_free(), which is inlined in rswitch_poll(). Since `skb` and `gq->skbs[gq->dirty]` are in fac | 0.6% | — |
| CVE-2024-38151 | MED 5.5 | microsoft windows_10_1507 Windows Kernel Information Disclosure Vulnerability | 0.6% | — |
| CVE-2024-38013 | MED 6.7 | microsoft windows_10_1507 Microsoft Windows Server Backup Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2024-35865 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: smb: client: fix potential UAF in smb2_is_valid_oplock_break() Skip sessions that are being teared down (status == SES_EXITING) to avoid UAF. | 0.6% | — |
| CVE-2024-29733 | LOW 2.7 | apache apache-airflow-providers-ftp Improper Certificate Validation vulnerability in Apache Airflow FTP Provider. The FTP hook lacks complete certificate validation in FTP_TLS connections, which can potentially be leveraged. Implementing proper certificate validation by passing context=ssl.crea | 0.6% | — |
| CVE-2024-26853 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT When a frame can not be transmitted in XDP_REDIRECT (e.g. due to a full queue), it is necessary to free it by calling xdp_return_frame_rx_nap | 0.6% | — |
| CVE-2023-52991 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: fix NULL pointer in skb_segment_list Commit 3a1296a38d0c ("net: Support GRO/GSO fraglist chaining.") introduced UDP listifyed GRO. The segmentation relies on frag_list being untouched w | 0.6% | — |
| CVE-2023-37453 | MED 4.6 | linux linux_kernel An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_descriptors in drivers/usb/core/sysfs.c. | 0.6% | — |
| CVE-2023-33161 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-33158 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2023-33149 | HIGH 7.8 | microsoft 365_apps Microsoft Office Graphics Remote Code Execution Vulnerability | 0.6% | — |
| CVE-2022-48828 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix ia_size underflow iattr::ia_size is a loff_t, which is a signed 64-bit type. NFSv3 and NFSv4 both define file size as an unsigned 64-bit type. Thus there is a range of valid file s | 0.6% | — |
| CVE-2022-34703 | HIGH 7.8 | microsoft windows_10 Windows Partition Management Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-31357 | HIGH 7.8 | juniper junos_os_evolved A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of t | 0.6% | — |
| CVE-2019-6653 | MED 5.4 | f5 big-iq_centralized_management There is a Stored Cross Site Scripting vulnerability in the undisclosed page of a BIG-IQ 6.0.0-6.1.0 or 5.2.0-5.4.0 system. The attack can be stored by users granted the Device Manager and Administrator roles. | 0.6% | — |
| CVE-2019-1834 | HIGH 7.4 | cisco aironet_access_point_firmware A vulnerability in the internal packet processing of Cisco Aironet Series Access Points (APs) could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected AP if the switch interface where the AP is connected has | 0.6% | — |
| CVE-2019-1761 | MED 4.3 | cisco ios A vulnerability in the Hot Standby Router Protocol (HSRP) subsystem of Cisco IOS and IOS XE Software could allow an unauthenticated, adjacent attacker to receive potentially sensitive information from an affected device. The vulnerability is due to insufficien | 0.6% | — |
| CVE-2017-3804 | MED 6.1 | cisco nx-os A vulnerability in Intermediate System-to-Intermediate System (IS-IS) protocol packet processing of Cisco Nexus 5000, 6000, and 7000 Series Switches software could allow an unauthenticated, adjacent attacker to cause a reload of the affected device. Switches i | 0.6% | — |
| CVE-2026-70178 | HIGH 8.5 | microsoft fabric Missing authorization in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-69857 | HIGH 8.5 | microsoft azure_cosmos_db Authorization bypass through user-controlled key in Azure Cosmos DB allows an authorized attacker to perform spoofing over a network. | 0.6% | — |
| CVE-2026-65818 | HIGH 8.5 | microsoft power_platform Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network. | 0.6% | — |
| CVE-2026-43083 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ioam6: fix OOB and missing lock When trace->type.bit6 is set: if (trace->type.bit6) { ... queue = skb_get_tx_queue(dev, skb); qdisc = rcu_dereference(queue- | 0.6% | — |
| CVE-2026-31636 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: rxrpc: fix RESPONSE authenticator parser OOB read rxgk_verify_authenticator() copies auth_len bytes into a temporary buffer and then passes p + auth_len as the parser limit to rxgk_do_verify | 0.6% | — |
| CVE-2026-28710 | CRIT 9.8 | acronis cyber_protect Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows) before build 41186. | 0.6% | — |
| CVE-2024-49051 | HIGH 7.8 | microsoft pc_manager Microsoft PC Manager Elevation of Privilege Vulnerability | 0.6% | — |