58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2025-37928 | HIGH 7.8 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: dm-bufio: don't schedule in atomic context A BUG was reported as below when CONFIG_DEBUG_ATOMIC_SLEEP and try_verify_in_tasklet are enabled. [ 129.444685][ T934] BUG: sleeping function cal | 0.7% | — |
| CVE-2024-35178 | HIGH 7.5 | jupyter jupyter_server The Jupyter Server provides the backend for Jupyter web applications. Jupyter Server on Windows has a vulnerability that lets unauthenticated attackers leak the NTLMv2 password hash of the Windows user running the Jupyter server. An attacker can crack this pas | 0.7% | — |
| CVE-2024-28148 | MED 4.3 | apache superset An authenticated user could potentially access metadata for a datasource they are not authorized to view by submitting a targeted REST API request.This issue affects Apache Superset: before 3.1.2. Users are recommended to upgrade to version 3.1.2 or above, wh | 0.7% | — |
| CVE-2024-21430 | MED 5.7 | microsoft windows_10_1507 Windows USB Attached SCSI (UAS) Protocol Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-36011 | HIGH 7.8 | microsoft windows_10_1507 Win32k Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-24953 | HIGH 7.8 | microsoft 365_apps Microsoft Excel Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-29132 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-40447 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2019-5594 | MED 6.1 | fortinet fortinac An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI. | 0.7% | — |
| CVE-2011-1583 | MED 6.9 | citrix xen Multiple integer overflows in tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allow local users to cause a denial of service and possibly execute arbitrary code via a crafted paravirtualised guest kernel image that triggers (1) a buffer overfl | 0.7% | — |
| CVE-2026-20821 | MED 6.2 | microsoft windows_10_1607 Exposure of sensitive information to an unauthorized actor in Windows Remote Procedure Call allows an unauthorized attacker to disclose information locally. | 0.7% | — |
| CVE-2025-24042 | HIGH 7.3 | microsoft visual_studio_code Visual Studio Code JS Debug Extension Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2025-21288 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2025-21272 | MED 6.5 | microsoft windows_10_1507 Windows COM Server Information Disclosure Vulnerability | 0.7% | — |
| CVE-2024-52056 | MED 6.5 | wowza streaming_engine Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system if the target directory contains an XML definition file. | 0.7% | — |
| CVE-2024-37087 | MED 5.3 | vmware cloud_foundation The vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-of-service condition. | 0.7% | — |
| CVE-2024-20658 | HIGH 7.8 | microsoft windows_10_1507 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-36770 | HIGH 7.8 | microsoft 3d_builder 3D Builder Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-26211 | MED 6.8 | fortinet fortisoar An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module. | 0.7% | — |
| CVE-2021-41347 | HIGH 7.8 | microsoft windows_10 Windows AppX Deployment Service Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2021-28349 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-28348 | HIGH 7.8 | microsoft windows_10 Windows GDI+ Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2021-26426 | HIGH 7.0 | microsoft windows_10 Windows User Account Profile Picture Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2020-1364 | HIGH 7.1 | microsoft windows_10 A denial of service vulnerability exists in the way that the WalletService handles files, aka 'Windows WalletService Denial of Service Vulnerability'. | 0.7% | — |
| CVE-2020-12826 | MED 5.3 | canonical ubuntu_linux A signal access-control issue was discovered in the Linux kernel before 5.6.5, aka CID-7395ea4e65c2. Because exec_id in include/linux/sched.h is only 32 bits, an integer overflow can interfere with a do_notify_parent protection mechanism. A child process can s | 0.7% | — |