57.961 CVE tracked
784 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
57.961 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2021-3348 | HIGH 7.0 | debian debian_linux nbd_add_socket in drivers/block/nbd.c in the Linux kernel through 5.10.12 has an ndb_queue_rq use-after-free that could be triggered by local attackers (with access to the nbd device) via an I/O request at a certain point during device setup, aka CID-b98e762e3 | 0.3% | — |
| CVE-2021-28820 | HIGH 8.8 | tibco ftl The FTL Server (tibftlserver), FTL C API, FTL Golang API, FTL Java API, and FTL .Net API components of TIBCO Software Inc.'s TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contain a vulnerability that theoretic | 0.3% | — |
| CVE-2021-28818 | HIGH 8.8 | tibco rendezvous The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), Rendezvous Secure C API, Rendezvous Java API, and Rendezvous .Net API components of TIBCO Software Inc.'s TIBCO Rendezv | 0.3% | — |
| CVE-2021-28817 | HIGH 8.8 | tibco rendezvous The Windows Installation component of TIBCO Software Inc.'s TIBCO Rendezvous and TIBCO Rendezvous Developer Edition contains a vulnerability that theoretically allows a low privileged attacker with local access on some versions of the Windows operating system | 0.3% | — |
| CVE-2021-27892 | HIGH 7.8 | ssh tectia_client SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation. ConnectSecure on Windows is affected. | 0.3% | — |
| CVE-2019-3633 | MED 5.5 | mcafee data_loss_prevention_endpoint Buffer overflow in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.2.8 allows local user to cause the Windows operating system to "blue screen" via a carefully constructed message sent to DLPe which bypasses DLPe internal checks and results i | 0.3% | — |
| CVE-2014-0747 | MED 6.8 | cisco unified_communications_manager The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to inject commands via unspecified CAPF programs, aka Bug ID CSCum95493. | 0.3% | — |
| CVE-2010-0532 | MED 6.9 | apple itunes Race condition in the installation package in Apple iTunes before 9.1 on Windows allows local users to gain privileges by replacing an unspecified file with a Trojan horse. | 0.3% | — |
| CVE-2026-8835 | HIGH 7.3 | ibm http_server IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service. | 0.3% | — |
| CVE-2026-83940 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-72963 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Modern Execution Server allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71342 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71333 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-71332 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70568 | HIGH 7.0 | microsoft windows_10_1607 Heap-based buffer overflow in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70567 | HIGH 7.0 | microsoft windows_11_24h2 Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70565 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows AF_UNIX Socket Provider allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-70562 | HIGH 7.0 | microsoft windows_10_1607 Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69896 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Error Reporting allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69891 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Media allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69889 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69866 | HIGH 7.0 | microsoft windows_10_1809 Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69838 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69834 | HIGH 7.0 | microsoft windows_10_1607 Use after free in Windows ALPC allows an authorized attacker to elevate privileges locally. | 0.3% | — |
| CVE-2026-69818 | HIGH 7.0 | microsoft windows_11_24h2 Use after free in Windows Win32K allows an authorized attacker to elevate privileges locally. | 0.3% | — |