IT
58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync

CVE Tracker

58.650 CVE

Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.

CVE Tracker
Identifier Severity, sort descending Product and flaw EPSS, sorted descending In KEV since, sort descending
CVE-2026-41098 HIGH 8.4 microsoft azure_stack_edge Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network. 0.8% —
CVE-2026-26119 HIGH 8.8 microsoft windows_admin_center Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. 0.8% —
CVE-2025-59249 HIGH 8.8 microsoft exchange_server Weak authentication in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network. 0.8% —
CVE-2025-29826 HIGH 7.3 microsoft dataverse Improper handling of insufficient permissions or privileges in Microsoft Dataverse allows an authorized attacker to elevate privileges over a network. 0.8% —
CVE-2024-35254 HIGH 7.1 microsoft azure_monitor_agent Azure Monitor Agent Elevation of Privilege Vulnerability 0.8% —
CVE-2024-26176 HIGH 7.8 microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability 0.8% —
CVE-2024-20344 MED 5.3 cisco imm_management_package A vulnerability in system resource management in Cisco UCS 6400 and 6500 Series Fabric Interconnects that are in Intersight Managed Mode (IMM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the Device Console UI 0.8% —
CVE-2023-21748 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8% —
CVE-2023-21675 HIGH 7.8 microsoft windows_10_1607 Windows Kernel Elevation of Privilege Vulnerability 0.8% —
CVE-2022-41079 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 0.8% —
CVE-2022-41078 HIGH 8.0 microsoft exchange_server Microsoft Exchange Server Spoofing Vulnerability 0.8% —
CVE-2021-36172 MED 4.3 fortinet fortiportal An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attacker who controls the producer of XML reports consumed by FortiPortal to trigger a denial of service or read arbi 0.8% —
CVE-2021-33034 HIGH 7.8 debian debian_linux In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value. 0.8% —
CVE-2021-29968 HIGH 8.1 mozilla firefox When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1. 0.8% —
CVE-2010-0307 MED 4.7 canonical ubuntu_linux The load_elf_binary function in fs/binfmt_elf.c in the Linux kernel before 2.6.32.8 on the x86_64 platform does not ensure that the ELF interpreter is available before a call to the SET_PERSONALITY macro, which allows local users to cause a denial of service ( 0.8% —
CVE-2007-4497 MED 5.5 canonical ubuntu_linux Unspecified vulnerability in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server be 0.8% —
CVE-2025-21292 HIGH 8.8 microsoft windows_10_1809 Windows Search Service Elevation of Privilege Vulnerability 0.8% —
CVE-2024-21442 HIGH 7.8 microsoft windows_10_21h2 Windows USB Print Driver Elevation of Privilege Vulnerability 0.8% —
CVE-2024-21434 HIGH 7.8 microsoft windows_10_1507 Microsoft Windows SCSI Class System File Elevation of Privilege Vulnerability 0.8% —
CVE-2021-36943 MED 4.0 microsoft azure_cyclecloud Azure CycleCloud Elevation of Privilege Vulnerability 0.8% —
CVE-2021-1517 MED 5.0 cisco webex_meetings_online A vulnerability in the multimedia viewer feature of Cisco Webex Meetings and Cisco Webex Meetings Server could allow an authenticated, remote attacker to bypass security protections. This vulnerability is due to unsafe handling of shared content within the mul 0.8% —
CVE-2019-3591 LOW 3.9 mcafee data_loss_prevention_endpoint Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in 0.8% —
CVE-2015-1044 LOW 3.3 vmware esxi vmware-authd (aka the Authorization process) in VMware Workstation 10.x before 10.0.5, VMware Player 6.x before 6.0.5, and VMware ESXi 5.0 through 5.5 allows attackers to cause a host OS denial of service via unspecified vectors. 0.8% —
CVE-2026-40372 CRIT 9.1 microsoft asp.net_core Improper verification of cryptographic signature in ASP.NET Core allows an unauthorized attacker to elevate privileges over a network. 0.8% —
CVE-2026-21523 HIGH 8.0 microsoft visual_studio_code Time-of-check time-of-use (toctou) race condition in GitHub Copilot and Visual Studio allows an authorized attacker to execute code over a network. 0.8% —