58.535 CVE tracked
796 Exploited now
188 Used by ransomware
Last sync
CVE Tracker
58.535 CVE
Ten vendors followed by CPE identifier, not by keyword: a CVE appears here once NVD says which products it affects — usually a few days after it is published.
| Identifier | Severity, sort descending | Product and flaw | EPSS, sorted ascending | In KEV since, sort descending |
|---|---|---|---|---|
| CVE-2024-21596 | MED 5.3 | juniper junos A Heap-based Buffer Overflow vulnerability in the Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). If an attacker sends a specific BGP UPDATE | 0.5% | — |
| CVE-2024-20745 | HIGH 7.8 | adobe premiere_pro Premiere Pro versions 24.1, 23.6.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu | 0.5% | — |
| CVE-2023-38175 | HIGH 7.8 | microsoft windows_defender Microsoft Windows Defender Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-35364 | HIGH 8.8 | microsoft windows_10_1809 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-28299 | MED 5.5 | microsoft visual_studio_2017 Visual Studio Spoofing Vulnerability | 0.5% | — |
| CVE-2022-44679 | MED 6.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-44674 | MED 5.5 | microsoft windows_10 Windows Bluetooth Driver Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-41074 | MED 5.5 | microsoft windows_10 Windows Graphics Component Information Disclosure Vulnerability | 0.5% | — |
| CVE-2022-23276 | HIGH 7.8 | microsoft sql_server SQL Server for Linux Containers Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2022-1652 | HIGH 7.8 | debian debian_linux Linux Kernel could allow a local attacker to execute arbitrary code on the system, caused by a concurrency use-after-free flaw in the bad_flp_intr function. By executing a specially-crafted program, an attacker could exploit this vulnerability to execute arbit | 0.5% | — |
| CVE-2021-40467 | HIGH 7.8 | microsoft windows_10 Windows Common Log File System Driver Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36134 | HIGH 7.4 | netop vision_pro Out of bounds write vulnerability in the JPEG parsing code of Netop Vision Pro up to and including 9.7.2 allows an adjacent unauthenticated attacker to write to arbitrary memory potentially leading to a Denial of Service (DoS). | 0.5% | — |
| CVE-2019-7308 | MED 5.6 | canonical ubuntu_linux kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks. | 0.5% | — |
| CVE-2026-54048 | MED 5.3 | apache impala Specifying tblproperties('avro.schema.url'=' http://...' ) or with a 'file:///' URI on a table in Impala 2.0.0 to 4.5.1 on all platforms allows an attacker to trigger a GET request to internal endpoints they may not have access to but that Impala does and the | 0.5% | — |
| CVE-2026-32637 | ND | Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarball containing parent-d | 0.5% | — |
| CVE-2026-21528 | MED 6.5 | microsoft azure_iot_explorer Binding to an unrestricted ip address in Azure IoT Explorer allows an unauthorized attacker to disclose information over a network. | 0.5% | — |
| CVE-2024-53146 | CRIT 9.1 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: NFSD: Prevent a potential integer overflow If the tag length is >= U32_MAX - 3 then the "length + 4" addition can result in an integer overflow. Address this by splitting the decoding into s | 0.5% | — |
| CVE-2024-30099 | HIGH 7.0 | microsoft windows_10_1507 Windows Kernel Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2023-5808 | HIGH 7.6 | hitachi vantara_hitachi_network_attached_storage SMU versions prior to 14.8.7825.01 are susceptible to unintended information disclosure, through URL manipulation. Authenticated users in a Storage administrative role are able to access HNAS configuration backup and diagnostic data, that would normally be bar | 0.5% | — |
| CVE-2023-45871 | HIGH 7.5 | debian debian_linux An issue was discovered in drivers/net/ethernet/intel/igb/igb_main.c in the IGB driver in the Linux kernel before 6.5.3. A buffer size may not be adequate for frames larger than the MTU. | 0.5% | — |
| CVE-2023-28235 | MED 6.8 | microsoft windows_10_1809 Windows Lock Screen Security Feature Bypass Vulnerability | 0.5% | — |
| CVE-2021-47136 | HIGH 8.6 | linux linux_kernel In the Linux kernel, the following vulnerability has been resolved: net: zero-initialize tc skb extension on allocation Function skb_ext_add() doesn't initialize created skb extension with any value and leaves it up to the user. However, since extension of t | 0.5% | — |
| CVE-2021-43239 | HIGH 7.1 | microsoft windows_10 Windows Recovery Environment Agent Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-42312 | HIGH 7.8 | microsoft defender_for_iot Microsoft Defender for IoT Elevation of Privilege Vulnerability | 0.5% | — |
| CVE-2021-36968 | HIGH 7.8 | microsoft windows_7 Windows DNS Elevation of Privilege Vulnerability | 0.5% | — |