58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2022-24546 | HIGH 7.8 | microsoft windows_10 Windows DWM Core Library Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-23014 | MED 6.5 | f5 big-ip_access_policy_manager On versions 16.1.x before 16.1.2 and 15.1.x before 15.1.4.1, when BIG-IP APM portal access is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End o | 0.8% | — |
| CVE-2022-20830 | MED 5.3 | cisco catalyst_sd-wan_manager A vulnerability in authentication mechanism of Cisco Software-Defined Application Visibility and Control (SD-AVC) on Cisco vManage could allow an unauthenticated, remote attacker to access the GUI of Cisco SD-AVC without authentication. This vulnerability exis | 0.8% | — |
| CVE-2021-0920 | MED 6.4 | debian debian_linux In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: | 0.8% | |
| CVE-2020-0733 | HIGH 7.8 | microsoft windows_malicious_software_removal_tool An elevation of privilege vulnerability exists when the Windows Malicious Software Removal Tool (MSRT) improperly handles junctions.To exploit this vulnerability, an attacker would first have to gain execution on the victim system, aka 'Windows Malicious Softw | 0.8% | — |
| CVE-2017-6601 | HIGH 7.1 | cisco firepower_extensible_operating_system A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command injection | 0.8% | — |
| CVE-2007-4573 | HIGH 7.2 | linux linux_kernel The IA32 system call emulation functionality in Linux kernel 2.4.x and 2.6.x before 2.6.22.7, when running on the x86_64 architecture, does not zero extend the eax register after the 32bit entry path to ptrace is used, which might allow local users to gain pri | 0.8% | — |
| CVE-2026-85893 | HIGH 8.8 | microsoft edge_chromium Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. | 0.8% | — |
| CVE-2026-85877 | HIGH 8.8 | microsoft windows_11_24h2 Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-83998 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-83992 | HIGH 8.8 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-81952 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-81376 | CRIT 9.6 | microsoft visual_studio_code Incomplete comparison with missing factors in Visual Studio Code allows an unauthorized attacker to bypass a security feature over a network. | 0.8% | — |
| CVE-2026-80085 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-80081 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-80080 | HIGH 8.8 | microsoft 365_apps Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-80077 | HIGH 8.8 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-80074 | HIGH 8.8 | microsoft remote_desktop_client Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78526 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78525 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78524 | HIGH 8.8 | microsoft 365_apps Out-of-bounds write in Microsoft Office allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78521 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78519 | HIGH 8.8 | microsoft 365_apps Use of uninitialized resource in Microsoft Office Outlook allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78517 | HIGH 8.8 | microsoft 365_apps Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |
| CVE-2026-78514 | HIGH 8.8 | microsoft 365_apps Use after free in Microsoft Office Word allows an unauthorized attacker to execute code over a network. | 0.8% | — |