58.639 CVE tracked
797 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.639 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2019-25044 | HIGH 7.8 | linux linux_kernel The block subsystem in the Linux kernel before 5.2 has a use-after-free that can lead to arbitrary code execution in the kernel context and privilege escalation, aka CID-c3e2219216c9. This is related to blk_mq_free_rqs and blk_cleanup_queue. | 0.6% | — |
| CVE-2019-19318 | MED 4.4 | canonical ubuntu_linux In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer, | 0.6% | — |
| CVE-2019-12636 | HIGH 8.8 | cisco sf200-24_firmware A vulnerability in the web-based management interface of Cisco Small Business Smart and Managed Switches could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to in | 0.6% | — |
| CVE-2019-11833 | MED 5.5 | canonical ubuntu_linux fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem. | 0.6% | — |
| CVE-2012-2016 | MED 4.9 | hp system_management_homepage Unspecified vulnerability in HP System Management Homepage (SMH) before 7.1.1 allows local users to obtain sensitive information via unknown vectors. | 0.6% | — |
| CVE-2026-69679 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-69637 | MED 5.7 | microsoft windows_10_1607 Out-of-bounds read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-69416 | MED 5.7 | microsoft windows_10_1607 Buffer over-read in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-69405 | MED 5.7 | microsoft windows_10_1607 Missing release of memory after effective lifetime in Windows DHCP Server allows an authorized attacker to deny service over an adjacent network. | 0.6% | — |
| CVE-2026-48895 | HIGH 7.2 | apache apisix URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session token. This issue affects Apache APISIX: from 3.0.0 through 3 | 0.6% | — |
| CVE-2026-44913 | HIGH 7.2 | apache nifi Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL commands using crafted naming. Manual quoted boundaries added in Apache NiFi 1.8.0 narrowed the scope of potent | 0.6% | — |
| CVE-2026-42498 | HIGH 7.3 | apache tomcat Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.2 | 0.6% | — |
| CVE-2026-41731 | HIGH 8.1 | redhat fuse JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserializat | 0.6% | — |
| CVE-2026-23980 | MED 6.5 | apache superset Improper Neutralization of Special Elements used in a SQL Command ('SQL Injection') vulnerability in Apache Superset allows an authenticated user with read access to conduct error-based SQL injection via the sqlExpression or where parameters. This issue affec | 0.6% | — |
| CVE-2025-48208 | HIGH 8.8 | apache hertzbeat Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache HertzBeat . The attacker needs to have an authenticated account with access, and the attack can only be triggered by crafting custom comman | 0.6% | — |
| CVE-2025-30377 | HIGH 8.4 | microsoft 365_apps Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.6% | — |
| CVE-2024-43513 | MED 6.4 | microsoft windows_10_1507 BitLocker Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-42110 | HIGH 7.5 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: ntb_netdev: Move ntb_netdev_rx_handler() to call netif_rx() from __netif_rx() The following is emitted when using idxd (DSA) dmanegine as the data mover for ntb_transport that ntb_netde | 0.6% | — |
| CVE-2024-41169 | HIGH 7.5 | apache zeppelin The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0 | 0.6% | — |
| CVE-2024-37973 | HIGH 8.8 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.6% | — |
| CVE-2024-28916 | HIGH 8.8 | microsoft xbox_gaming_services Xbox Gaming Services Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2022-20677 | MED 5.5 | cisco ios Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system | 0.6% | — |
| CVE-2021-33784 | HIGH 7.8 | microsoft windows_10 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33759 | HIGH 7.8 | microsoft windows_10 Windows Desktop Bridge Elevation of Privilege Vulnerability | 0.6% | — |
| CVE-2021-33743 | HIGH 7.8 | microsoft windows_10 Windows Projected File System Elevation of Privilege Vulnerability | 0.6% | — |