58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2023-47104 | CRIT 9.8 | vareille tinyfiledialogs tinyfiledialogs (aka tiny file dialogs) before 3.15.0 allows shell metacharacters (such as a backquote or a dollar sign) in titles, messages, and other input data. NOTE: this issue exists because of an incomplete fix for CVE-2020-36767, which only considered s | 0.7% | — |
| CVE-2023-32018 | HIGH 7.8 | microsoft windows_11_22h2 Windows Hello Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-32008 | HIGH 7.8 | microsoft windows_10_1507 Windows Resilient File System (ReFS) Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29370 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29367 | HIGH 7.8 | microsoft windows_server_2012 iSCSI Target WMI Provider Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29366 | HIGH 7.8 | microsoft windows_10_21h2 Windows Geolocation Service Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2023-29365 | HIGH 7.8 | microsoft windows_10_1507 Windows Media Remote Code Execution Vulnerability | 0.7% | — |
| CVE-2022-45052 | HIGH 8.8 | axiell iguana A Local File Inclusion vulnerability has been found in Axiell Iguana CMS. Due to insufficient neutralisation of user input on the url parameter on the Proxy.type.php endpoint, external users are capable of accessing files on the server. | 0.7% | — |
| CVE-2022-35706 | HIGH 7.8 | adobe bridge Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction | 0.7% | — |
| CVE-2022-22449 | MED 5.3 | ibm security_verify_governance IBM Security Verify Governance, Identity Manager 10.01 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM | 0.7% | — |
| CVE-2021-47244 | HIGH 8.2 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: Fix out of bounds when parsing TCP options The TCP option parser in mptcp (mptcp_get_options) could read one byte out of bounds. When the length is 1, the execution flow gets into the | 0.7% | — |
| CVE-2021-43389 | MED 5.5 | debian debian_linux An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. | 0.7% | — |
| CVE-2012-4131 | MED 4.6 | cisco nx-os Directory traversal vulnerability in tar in Cisco NX-OS allows local users to access arbitrary files via crafted command-line arguments, aka Bug IDs CSCty07157, CSCty07159, CSCty07162, and CSCty07164. | 0.7% | — |
| CVE-2026-85885 | CRIT 9.9 | microsoft 365_copilot Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. | 0.7% | — |
| CVE-2026-57985 | HIGH 7.6 | microsoft edge_chromium Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. | 0.7% | — |
| CVE-2026-39813 | CRIT 9.8 | fortinet fortisandbox A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests. | 0.7% | — |
| CVE-2026-3536 | HIGH 8.8 | google chrome Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.7% | — |
| CVE-2025-55248 | MED 4.8 | microsoft .net Inadequate encryption strength in .NET, .NET Framework, Visual Studio allows an authorized attacker to disclose information over a network. | 0.7% | — |
| CVE-2025-21213 | MED 4.6 | microsoft windows_10_1507 Secure Boot Security Feature Bypass Vulnerability | 0.7% | — |
| CVE-2024-26782 | CRIT 9.8 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the new socket has the same | 0.7% | — |
| CVE-2024-20721 | MED 5.5 | adobe acrobat Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current | 0.7% | — |
| CVE-2023-35331 | MED 6.5 | microsoft windows_server_2012 Windows Local Security Authority (LSA) Denial of Service Vulnerability | 0.7% | — |
| CVE-2023-21774 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-21772 | HIGH 7.8 | microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability | 0.7% | — |
| CVE-2023-20174 | MED 4.9 | cisco identity_services_engine Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to read arbitrary files or conduct a server-side request forgery (SSRF) attack through an affected device. To e | 0.7% | — |