58.650 CVE tracked
799 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.650 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted descending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-3538 | HIGH 8.8 | google chrome Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical) | 0.8% | — |
| CVE-2026-21253 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Mailslot File System allows an authorized attacker to elevate privileges locally. | 0.8% | — |
| CVE-2025-26642 | HIGH 7.8 | microsoft 365_apps Out-of-bounds read in Microsoft Office allows an unauthorized attacker to execute code locally. | 0.8% | — |
| CVE-2022-37376 | LOW 3.3 | foxit pdf_editor This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Editor 11.1.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicio | 0.8% | — |
| CVE-2022-23013 | HIGH 8.8 | f5 big-ip_domain_name_system On BIG-IP DNS & GTM version 16.x before 16.1.0, 15.1.x before 15.1.4, 14.1.x before 14.1.4.4, and all versions of 13.1.x, 12.1.x, and 11.6.x, a DOM-based cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility | 0.8% | — |
| CVE-2020-3367 | HIGH 7.8 | cisco asyncos A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevate privileges to root. This vulnerability | 0.8% | — |
| CVE-2019-1920 | HIGH 7.4 | cisco access_points A vulnerability in the 802.11r Fast Transition (FT) implementation for Cisco IOS Access Points (APs) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected interface. The vulnerability is due to a | 0.8% | — |
| CVE-2018-6661 | HIGH 7.8 | mcafee true_key DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain privilege elevation via not verifying a particular DLL file signature. | 0.8% | — |
| CVE-2017-6659 | HIGH 8.8 | cisco prime_collaboration_assurance A vulnerability in the web-based management interface of Cisco Prime Collaboration Assurance could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Informa | 0.8% | — |
| CVE-2017-6634 | HIGH 8.8 | cisco industrial_ethernet_1000_series_firmware A vulnerability in the Device Manager web interface of Cisco Industrial Ethernet 1000 Series Switches 1.3 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of an affected system. The vulnerabil | 0.8% | — |
| CVE-2015-4481 | LOW 3.3 | mozilla firefox Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during | 0.8% | — |
| CVE-2026-31995 | MED 5.3 | openclaw openclaw OpenClaw versions 2026.1.21 prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension's Windows shell fallback mechanism that allows attackers to inject arbitrary commands through tool-provided arguments. When spawn failures trigger | 0.8% | — |
| CVE-2025-64667 | MED 5.3 | microsoft exchange_server User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. | 0.8% | — |
| CVE-2025-27526 | MED 6.5 | apache inlong Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through 2.1.0. This vulnerability which can lead to JDBC Vulnerability URLEncdoe and backspace bypass. Users are advised to upgrade to Apache InLon | 0.8% | — |
| CVE-2023-52738 | MED 5.3 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/fence: Fix oops due to non-matching drm_sched init/fini Currently amdgpu calls drm_sched_fini() from the fence driver sw fini routine - such function is expected to be called only | 0.8% | — |
| CVE-2022-41064 | MED 5.8 | microsoft .net_framework .NET Framework Information Disclosure Vulnerability | 0.8% | — |
| CVE-2022-26802 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26801 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26796 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26792 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2022-26787 | HIGH 7.8 | microsoft windows_10 Windows Print Spooler Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-40123 | MED 4.3 | cisco identity_services_engine A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative read-only privileges to download files that should be restricted. This vulnerability is due to incor | 0.8% | — |
| CVE-2021-27090 | HIGH 7.8 | microsoft windows_10 Windows Secure Kernel Mode Elevation of Privilege Vulnerability | 0.8% | — |
| CVE-2021-21990 | MED 6.1 | vmware workspace_one_unified_endpoint_management VMware Workspace one UEM console (2102 prior to 21.2.0.8, 2101 prior to 21.1.0.14, 2011 prior to 20.11.0.27, 2010 prior to 20.10.0.16,2008 prior to 20.8.0.28, 2007 prior to 20.7.0.14,2006 prior to 20.6.0.19, 2005 prior to 20.5.0.46, 2004 prior to 20.4.0.21, 20 | 0.8% | — |
| CVE-2021-1569 | MED 6.5 | cisco jabber Multiple vulnerabilities in Cisco Jabber for Windows, Cisco Jabber for Mac, and Cisco Jabber for mobile platforms could allow an attacker to access sensitive information or cause a denial of service (DoS) condition. For more information about these vulnerabili | 0.8% | — |