58.352 CVE tracked
792 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.352 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2026-20863 | HIGH 7.0 | microsoft windows_11_23h2 Double free in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20842 | HIGH 7.0 | microsoft windows_10_21h2 Use after free in Windows DWM allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20822 | HIGH 7.8 | microsoft windows_10_1607 Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2026-20130 | CRIT 10.0 | cisco identity_services_engine As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have conducted a comprehensive internal security review. This review | 0.4% | — |
| CVE-2026-19303 | HIGH 8.1 | langflow langflow IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to delete arbitrary local files or directories due to improper limitation of a pathname to a restricted directory. | 0.4% | — |
| CVE-2025-59290 | HIGH 7.8 | microsoft windows_10_21h2 Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-58716 | HIGH 8.8 | microsoft windows_10_1507 Improper input validation in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-58715 | HIGH 8.8 | microsoft windows_10_1507 Integer overflow or wraparound in Microsoft Windows Speech allows an authorized attacker to elevate privileges locally. | 0.4% | — |
| CVE-2025-38608 | HIGH 8.6 | debian debian_linux In the Linux kernel, the following vulnerability has been resolved: bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls When sending plaintext data, we initially calculated the corresponding ciphertext length. However, if we later reduced th | 0.4% | — |
| CVE-2024-30058 | MED 5.4 | microsoft edge_chromium Microsoft Edge (Chromium-based) Spoofing Vulnerability | 0.4% | — |
| CVE-2024-20431 | MED 5.8 | cisco secure_firewall_threat_defense A vulnerability in the geolocation access control feature of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass an access control policy. This vulnerability is due to improper assignment of geolocation da | 0.4% | — |
| CVE-2024-20361 | MED 5.8 | cisco secure_firewall_management_center A vulnerability in the Object Groups for Access Control Lists (ACLs) feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass configured access controls on managed devices that are running Cisco Fire | 0.4% | — |
| CVE-2024-20293 | MED 5.8 | cisco adaptive_security_appliance_software A vulnerability in the activation of an access control list (ACL) on Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass the protection that is offered by | 0.4% | — |
| CVE-2024-0007 | MED 6.8 | paloaltonetworks pan-os A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS software enables a malicious authenticated read-write administrator to store a JavaScript payload using the web interface on Panorama appliances. This enables the impersonation of another | 0.4% | — |
| CVE-2023-32050 | HIGH 7.0 | microsoft windows_server_2008 Windows Installer Elevation of Privilege Vulnerability | 0.4% | — |
| CVE-2023-25603 | MED 5.4 | fortinet fortiadc A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacker to carry out privileged actions and retrieve sensitive information via crafted | 0.4% | — |
| CVE-2022-41738 | HIGH 7.5 | ibm spectrum_scale_container_native_storage_access IBM Storage Scale Container Native Storage Access 5.1.2.1 -through 5.1.7.0 could allow an attacker to initiate connections to containers from external networks. IBM X-Force ID: 237812. | 0.4% | — |
| CVE-2022-34242 | HIGH 7.8 | adobe character_animator Adobe Character Animator version 4.4.7 (and earlier) and 22.4 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage | 0.4% | — |
| CVE-2022-28388 | MED 5.5 | debian debian_linux usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. | 0.4% | — |
| CVE-2021-38160 | HIGH 7.8 | debian debian_linux In drivers/char/virtio_console.c in the Linux kernel before 5.13.4, data corruption or loss can be triggered by an untrusted device that supplies a buf->len value exceeding the buffer size. NOTE: the vendor indicates that the cited data corruption is not a vul | 0.4% | — |
| CVE-2021-1237 | HIGH 7.8 | cisco anyconnect_secure_mobility_client A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker w | 0.4% | — |
| CVE-2020-3972 | LOW 3.3 | vmware tools VMware Tools for macOS (11.x.x and prior before 11.1.1) contains a denial-of-service vulnerability in the Host-Guest File System (HGFS) implementation. Successful exploitation of this issue may allow attackers with non-admin privileges on guest macOS virtual m | 0.4% | — |
| CVE-2020-36163 | CRIT 9.3 | veritas netbackup An issue was discovered in Veritas NetBackup and OpsCenter through 8.3.0.1. NetBackup processes using Strawberry Perl attempt to load and execute libraries from paths that do not exist by default on the Windows operating system. By default, on Windows systems, | 0.4% | — |
| CVE-2020-18171 | HIGH 8.8 | techsmith snagit TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. | 0.4% | — |
| CVE-2019-0070 | HIGH 8.8 | juniper junos An Improper Input Validation weakness allows a malicious local attacker to elevate their permissions to take control of other portions of the NFX platform they should not be able to access, and execute commands outside their authorized scope of control. This l | 0.4% | — |